CVE

Id
10607  
CVE No.
CVE-2004-2181  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.  
Phase
Assigned (20050711)  
Votes
REVIEWING(1) Christey  
Comments
Christey> The view_user.php/sort_by vector is covered by several CVEs. | Need to figure out how to handle this.