Vulnerability Details CVE-2008-4431
SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/functions.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2008-4431
-
-
cpe:2.3:a:icebb:icebb:0.9
-
cpe:2.3:a:icebb:icebb:0.9.1
-
cpe:2.3:a:icebb:icebb:0.9.2
-
cpe:2.3:a:icebb:icebb:0.9.2.1
-
cpe:2.3:a:icebb:icebb:0.9.3
-
cpe:2.3:a:icebb:icebb:0.9.3.1
-
cpe:2.3:a:icebb:icebb:1.0