CVE-2004-0036
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.
Vulnerabilidad de inyección de SQL en calendar.php de vBulletin Forum 2.3.x permite a atacantes remotos robar información sensible mediante el parámetro eventid
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-01-07 CVE Reserved
- 2004-01-20 CVE Published
- 2023-08-09 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=107340358202123&w=2 | Mailing List | |
http://www.osvdb.org/3344 | Vdb Entry | |
http://www.securityfocus.com/bid/9360 | Vdb Entry | |
http://www.vbulletin.com/forum/showthread.php?postid=588825 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/14144 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|