CVE-2012-4034

high
Published 2012-08-12 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.pbboard.com/forums/t10353.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/50153

Application impact

VendorProductVersionsFixed
pbboardpbboard2.1.4

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.