Vulnerability Details CVE-2009-0882
Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.1%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2009-0882
-
cpe:2.3:a:roman_bogorodskiy:nforum:1.5