Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2456
CVE-2004-2456
Description
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.
Affected products
6cpe:2.3:a:minibb:minibb:1.2:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:minibb:minibb:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:minibb:minibb:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:minibb:minibb:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:minibb:minibb:1.7:*:*:*:*:*:*:*
- cpe:2.3:a:minibb:minibb:1.7a:*:*:*:*:*:*:*
- cpe:2.3:a:minibb:minibb:1.7c:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- securitytracker.com/idnvdExploitPatch
- www.osvdb.org/11711nvdExploitPatch
- www.securityfocus.com/bid/11688nvdExploitPatch
- www.minibb.net/forums/index.phpnvdVendor Advisory
- www.minibb.net/forums/index.phpnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/18080nvd
News mentions
0No linked articles in our index yet.