peter bassill · operator
$ cve CVE-2004-1406 JSON

CVE-2004-1406 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.44% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
ikonboard.comikonboard

Public exploits

SourceTitleDate
exploit-dbIkonBoard 3.x - Multiple SQL Injections2004-12-16

References

→ the Explorer  ·  watch your stack  ·  NVD