CVE-2004-1406 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.44% — more likely to be exploited than 84% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ikonboard.com | ikonboard |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IkonBoard 3.x - Multiple SQL Injections | 2004-12-16 |
References
- http://marc.info/?l=bugtraq&m=110321654705580&w=2
- http://secunia.com/advisories/13513
- http://www.securityfocus.com/bid/11982
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18533
- http://marc.info/?l=bugtraq&m=110321654705580&w=2
- http://secunia.com/advisories/13513
- http://www.securityfocus.com/bid/11982
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18533
→ the Explorer · watch your stack · NVD