peter bassill · operator
$ cve CVE-2012-4034 JSON

CVE-2012-4034 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.51% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2012-08-12
Last modified2026-06-16

Affected (1)

VendorProduct
pbboardpbboard

Public exploits

SourceTitleDate
exploit-dbPBBoard - 'index.php' Multiple SQL Injections2012-08-08

References

→ the Explorer  ·  watch your stack  ·  NVD