peter bassill · operator
$ cve CVE-2012-1603 JSON

CVE-2012-1603 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 73)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr parameter in the findUsers function, (2) id parameter in the isIdAvailable function, or (3) username parameter in the getGreetings function.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.45% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2012-10-01
Last modified2026-06-16

Affected (1)

VendorProduct
nextbbsnextbbs

Public exploits

SourceTitleDate
exploit-dbNextBBS 0.6 - 'ajaxserver.php' Multiple SQL Injections2012-03-27

References

→ the Explorer  ·  watch your stack  ·  NVD