CVE-2005-2673: SQL Injection
SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2673?
CVE-2005-2673 is considered a critical SQL injection vulnerability that can allow remote authenticated attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-2673?
To fix CVE-2005-2673, upgrade WoltLab Burning Board to version 2.3.4 or later, which resolves this SQL injection issue.
What software versions are affected by CVE-2005-2673?
CVE-2005-2673 affects WoltLab Burning Board versions 2.2.2 and 2.2.3.
How can attackers exploit CVE-2005-2673?
Attackers can exploit CVE-2005-2673 by sending specially crafted requests that manipulate the x or y parameters in modcp.php.
Is authentication required to exploit CVE-2005-2673?
Yes, exploitation of CVE-2005-2673 requires the attacker to be authenticated to the WoltLab Burning Board system.