CVE-2011-4066

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
04/11/2011
Last modified:
11/04/2025

Description

SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sir:gnuboard:*:*:*:*:*:*:*:* 4.33.02 (including)
cpe:2.3:a:sir:gnuboard:3.30:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.31:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.32:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.33:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.34:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.35:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.36:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.37:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.38:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.39:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:3.40:*:*:*:*:*:*:*
cpe:2.3:a:sir:gnuboard:4.31.03:*:*:*:*:*:*:*