VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-2178

CVE-2004-2178

Description

DevoyBB Web Forum 1.0.0 is vulnerable to SQL injection via unknown vectors, allowing remote attackers to execute arbitrary SQL commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DevoyBB Web Forum 1.0.0 is vulnerable to SQL injection via unknown vectors, allowing remote attackers to execute arbitrary SQL commands.

Vulnerability

DevoyBB Web Forum version 1.0.0 contains an SQL injection vulnerability. The official description states that remote attackers can execute arbitrary SQL commands via unknown vectors, indicating that the injection point(s) and required conditions were not disclosed in the publicly available reference [1]. The vulnerable version is 1.0.0.

Exploitation

The exploitation vector is not detailed in the available sources [1]. Based on the description, an attacker can trigger the vulnerability remotely over the network. No authentication or user interaction is explicitly mentioned, suggesting that the attack surface may be unauthenticated. The exact sequence of steps is unknown.

Impact

Successful exploitation allows an attacker to execute arbitrary SQL commands against the forum's database. This typically leads to information disclosure (extraction of user credentials, forum content), data manipulation, and potentially full compromise of the database server, depending on configuration and permissions.

Mitigation

The reference [1] does not provide a fix or workaround. As an early-2000s vulnerability, it is likely resolved in a later version of DevoyBB Web Forum, but no specific patched version is documented. Users running version 1.0.0 should upgrade to a supported release or discontinue use if the software is no longer maintained.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:devoybb:devoybb_web_forum:1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:devoybb:devoybb_web_forum:1.0:*:*:*:*:*:*:*
    • (no CPE)range: =1.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.