Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-1234
CVE-2005-1234
Description
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.
Affected products
2cpe:2.3:a:phpbb_group:phpbb-auction:1.0m:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:phpbb_group:phpbb-auction:1.0m:*:*:*:*:*:*:*
- cpe:2.3:a:phpbb_group:phpbb-auction:1.2m:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/15029nvdExploitPatch
- securitytracker.com/idnvdExploit
- www.osvdb.org/15704nvdExploit
- www.phpbb-auction.com/sutra5600.htmlnvdExploit
- www.securityfocus.com/bid/13283nvdExploit
- www.securityfocus.com/bid/13284nvdExploit
- www.snkenjoi.com/secadv/secadv9.txtnvdExploit
- www.aria-security.net/advisory/phpauction.txtnvd
- www.osvdb.org/15705nvd
- www.securityfocus.com/archive/1/441190/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/20203nvd
News mentions
0No linked articles in our index yet.