Back

CVE-2004-2145

SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
pd9_software megabbs 2
pd9_software megabbs 2.1

GitHub Security Advisory GHSA-mfr9-w3c9-m84j

SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.32%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub