CVE Vulnerabilities

CVE-2007-1725

Published: Mar 28, 2007 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.

Affected Software

Name Vendor Start Version End Version
Icebb Icebb 1.0_rc_5 (including) 1.0_rc_5 (including)

References