CVE-2012-4034

N/A Unknown
Published: August 12, 2012 Modified: April 29, 2026
View on NVD

Description

Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/84480
Source: cve@mitre.org
http://secunia.com/advisories/50153
Source: cve@mitre.org
Vendor Advisory
http://www.pbboard.com/forums/t10352.html
Source: cve@mitre.org
URL Repurposed
http://www.pbboard.com/forums/t10353.html
Source: cve@mitre.org
Vendor Advisory URL Repurposed
http://www.securityfocus.com/bid/54916
Source: cve@mitre.org
Exploit
https://www.htbridge.com/advisory/HTB23101
Source: cve@mitre.org
Exploit
http://osvdb.org/84480
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/50153
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.pbboard.com/forums/t10352.html
Source: af854a3a-2127-422b-91ae-364da2661108
URL Repurposed
http://www.pbboard.com/forums/t10353.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory URL Repurposed
http://www.securityfocus.com/bid/54916
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/77501
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.htbridge.com/advisory/HTB23101
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.5%
83th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

pbboard