CVE-2010-4812

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
08/07/2011
Last modified:
11/04/2025

Description

Multiple SQL injection vulnerabilities in 6kbbs 8.0 build 20100901 allow remote attackers to execute arbitrary SQL commands via the (1) tids[] parameter to ajaxadmin.php and the (2) msgids[] parameter to ajaxmember.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:6kbbs:6kbbs:8.0:*:*:*:*:*:*:*