{"api_version":"1","generated_at":"2026-07-23T05:23:33+00:00","cve":"CVE-2005-3259","urls":{"html":"https://cve.report/CVE-2005-3259","api":"https://cve.report/api/cve/CVE-2005-3259.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3259","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3259"},"summary":{"title":"CVE-2005-3259","description":"Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) \"search this thread\" feature, (3) \"search for posts\" feature, (4) \"forgot password\" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-10-20 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/19965","name":"http://www.osvdb.org/19965","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/19967","name":"http://www.osvdb.org/19967","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=112907535528616&w=2","name":"http://marc.info/?l=bugtraq&m=112907535528616&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'versatileBulletinBoard V1.0.0 RC2 (possibly prior versions)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/19968","name":"http://www.osvdb.org/19968","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/19963","name":"http://www.osvdb.org/19963","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15068","name":"http://www.securityfocus.com/bid/15068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"VersatileBulletinBoard Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/19962","name":"http://www.osvdb.org/19962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/19966","name":"http://www.osvdb.org/19966","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/17174/","name":"http://secunia.com/advisories/17174/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - versatileBulletinBoard Cross-Site Scripting and SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rgod.altervista.org/versatile100RC2.html","name":"http://rgod.altervista.org/versatile100RC2.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.osvdb.org/19964","name":"http://www.osvdb.org/19964","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3259","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3259","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3259","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"versatilebulletinboard","cpe5":"versatilebulletinboard","cpe6":"1.0.0.rc2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:01:59.137Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19962","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19962"},{"name":"15068","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15068"},{"name":"19963","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19963"},{"name":"19966","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19966"},{"name":"19964","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19964"},{"name":"20051010 versatileBulletinBoard V1.0.0 RC2 (possibly prior versions)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112907535528616&w=2"},{"name":"19968","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19968"},{"name":"19967","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19967"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://rgod.altervista.org/versatile100RC2.html"},{"name":"17174","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17174/"},{"name":"19965","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19965"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) \"search this thread\" feature, (3) \"search for posts\" feature, (4) \"forgot password\" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19962","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19962"},{"name":"15068","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15068"},{"name":"19963","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19963"},{"name":"19966","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19966"},{"name":"19964","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19964"},{"name":"20051010 versatileBulletinBoard V1.0.0 RC2 (possibly prior versions)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112907535528616&w=2"},{"name":"19968","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19968"},{"name":"19967","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19967"},{"tags":["x_refsource_MISC"],"url":"http://rgod.altervista.org/versatile100RC2.html"},{"name":"17174","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17174/"},{"name":"19965","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19965"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3259","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) \"search this thread\" feature, (3) \"search for posts\" feature, (4) \"forgot password\" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19962","refsource":"OSVDB","url":"http://www.osvdb.org/19962"},{"name":"15068","refsource":"BID","url":"http://www.securityfocus.com/bid/15068"},{"name":"19963","refsource":"OSVDB","url":"http://www.osvdb.org/19963"},{"name":"19966","refsource":"OSVDB","url":"http://www.osvdb.org/19966"},{"name":"19964","refsource":"OSVDB","url":"http://www.osvdb.org/19964"},{"name":"20051010 versatileBulletinBoard V1.0.0 RC2 (possibly prior versions)","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112907535528616&w=2"},{"name":"19968","refsource":"OSVDB","url":"http://www.osvdb.org/19968"},{"name":"19967","refsource":"OSVDB","url":"http://www.osvdb.org/19967"},{"name":"http://rgod.altervista.org/versatile100RC2.html","refsource":"MISC","url":"http://rgod.altervista.org/versatile100RC2.html"},{"name":"17174","refsource":"SECUNIA","url":"http://secunia.com/advisories/17174/"},{"name":"19965","refsource":"OSVDB","url":"http://www.osvdb.org/19965"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3259","datePublished":"2005-10-20T04:00:00.000Z","dateReserved":"2005-10-20T00:00:00.000Z","dateUpdated":"2024-08-07T23:01:59.137Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-20 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:versatilebulletinboard:versatilebulletinboard:1.0.0.rc2:*:*:*:*:*:*:*","matchCriteriaId":"76C60672-D4A1-4199-A4FD-7518BF0B32E8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3259","Ordinal":"1","Title":"CVE-2005-3259","CVE":"CVE-2005-3259","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3259","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) \"search this thread\" feature, (3) \"search for posts\" feature, (4) \"forgot password\" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.","Type":"Description","Title":"CVE-2005-3259"},{"CveYear":"2005","CveId":"3259","Ordinal":"2","NoteData":"2005-10-20","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3259","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}