Back

CVE-2004-1864

SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.

Published: Mar 26, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
xmb_forum xmb 1.8_sp3
xmb_forum xmb 1.9_beta

GitHub Security Advisory GHSA-q95m-g3gg-q299

SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.18%

Top 19% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub