peter bassill · operator
$ cve CVE-2004-0323 JSON

CVE-2004-0323 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS4.02% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
xmb forumxmb

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD