CVE-2005-3022: SQL Injection
Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to help.php, (7) rvt parameter to language.php, (8) keep parameter to phrase.php, or (9) updateprofilepic parameter to usertools.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3022?
CVE-2005-3022 has a high severity rating due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-3022?
To fix CVE-2005-3022, upgrade vBulletin to version 3.0.9 or later, which addresses these SQL injection vulnerabilities.
What types of vulnerabilities are associated with CVE-2005-3022?
CVE-2005-3022 is associated with multiple SQL injection vulnerabilities in various vBulletin scripts.
Which versions of vBulletin are affected by CVE-2005-3022?
CVE-2005-3022 affects vBulletin versions up to and including 3.0.8.
What is the impact of exploiting CVE-2005-3022?
Exploiting CVE-2005-3022 allows attackers to manipulate SQL queries, potentially leading to data compromise or unauthorized access.