CVE

Id
14890  
CVE No.
CVE-2005-3686  
Status
Candidate  
Description
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.  
Phase
Assigned (20051119)  
Votes
None (candidate not yet proposed)  
Comments