CVE
- Id
- 1703
- CVE No.
- CVE-2000-0125
- Status
- Candidate
- Description
- wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.
- Phase
- Proposed (20000208)
- Votes
- ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Christey, Wall
- Comments
- Frech> XF:wwwthreads-sql-command-privs(4011) | Christey> CONFIRM:http://www.wwwthreads.com/perl/showflat.pl?Cat=&Board=info&Number=9932&page=1&view=collapsed&sb=5