CVE-2005-3369: SQL Injection
Multiple SQL injection vulnerabilities in the Info-DB module (infodb.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3369?
CVE-2005-3369 is considered a high severity vulnerability due to its potential for allowing remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-3369?
To fix CVE-2005-3369, upgrade to a version of Woltlab Burning Board that is not affected, specifically version 2.8 or later.
Which versions of Woltlab Burning Board are affected by CVE-2005-3369?
CVE-2005-3369 affects Woltlab Burning Board versions 2.7 and earlier.
What types of attacks can be executed due to CVE-2005-3369?
Due to CVE-2005-3369, attackers can perform SQL injection attacks that may allow them to manipulate the database and execute arbitrary SQL commands.
Is file upload possible through CVE-2005-3369?
Yes, CVE-2005-3369 potentially allows attackers to upload files by exploiting the affected parameters in the Info-DB module.