Back
CVE-2004-1515
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| jelsoft | vbulletin | 3.0.0 |
| jelsoft | vbulletin | 3.0.0_beta_2 |
| jelsoft | vbulletin | 3.0.0_can4 |
| jelsoft | vbulletin | 3.0.0_rc4 |
| jelsoft | vbulletin | 3.0.1 |
| jelsoft | vbulletin | 3.0.2 |
| jelsoft | vbulletin | 3.0.3 |
| jelsoft | vbulletin | 3.0.4 |
| jelsoft | vbulletin | 3.0.5 |
| jelsoft | vbulletin | 3.0.6 |
| jelsoft | vbulletin | 3.0_beta_2 |
GitHub Security Advisory GHSA-rphm-9gg2-wrrv
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote...
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.01%
Top 40% most likely to be exploited
Threat Score
30.3 / 100
Data Sources
NVD
EPSS
GitHub