CVE-2005-0661: SQL Injection
SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0661?
CVE-2005-0661 has a high severity rating due to the potential for remote SQL command execution.
How do I fix CVE-2005-0661?
To fix CVE-2005-0661, upgrade to a version of Woltlab Burning Board that is not vulnerable, specifically versions above 2.3.0.
Which versions of Woltlab Burning Board are affected by CVE-2005-0661?
The versions of Woltlab Burning Board affected by CVE-2005-0661 are 2.0.3 through 2.3.0.
Can CVE-2005-0661 be exploited remotely?
Yes, CVE-2005-0661 can be exploited remotely if an attacker sends manipulated requests containing SQL commands.
What are the potential impacts of exploiting CVE-2005-0661?
Exploitation of CVE-2005-0661 can lead to unauthorized access to the database and execution of arbitrary SQL commands.