CVE-2004-1515
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
- Affected products
- Vbulletin
- Jelsoft Vbulletin
- = 3.0.0, 3.0.0_beta_2, 3.0.0_can4, 3.0.0_rc4, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0_beta_2
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 1.0% (60th percentile)
- NVD status
- Modified
- Published
- 2005-02-19
CVE-2004-1515 at NVD
1 known exploit for CVE-2004-1515
Proof-of-concept code and exploit modules indexed by Sploitus