Back

CVE-2005-1051

SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (18)

Vendor Product Version
punbb punbb 1.0
punbb punbb 1.0.1
punbb punbb 1.0_alpha
punbb punbb 1.0_beta1
punbb punbb 1.0_beta2
punbb punbb 1.0_beta3
punbb punbb 1.0_rc1
punbb punbb 1.0_rc2
punbb punbb 1.1
punbb punbb 1.1.1
punbb punbb 1.1.2
punbb punbb 1.1.3
punbb punbb 1.1.4
punbb punbb 1.1.5
punbb punbb 1.2.1
punbb punbb 1.2.2
punbb punbb 1.2.3
punbb punbb 1.2.4

GitHub Security Advisory GHSA-9c26-35wc-9jmc

SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to...

Risk Scores

CVSS Score 6.5 / 10
EPSS Score 2.07%

Top 20% most likely to be exploited

Threat Score 26.6 / 100

Data Sources

NVD EPSS GitHub