Back

CVE-2005-2193

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.

Published: Jul 11, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (18)

Vendor Product Version
punbb punbb 1.0
punbb punbb 1.0.1
punbb punbb 1.0_alpha
punbb punbb 1.0_beta1
punbb punbb 1.0_beta2
punbb punbb 1.0_beta3
punbb punbb 1.0_rc1
punbb punbb 1.0_rc2
punbb punbb 1.1
punbb punbb 1.1.1
punbb punbb 1.1.2
punbb punbb 1.1.3
punbb punbb 1.1.4
punbb punbb 1.1.5
punbb punbb 1.2.1
punbb punbb 1.2.2
punbb punbb 1.2.3
punbb punbb 1.2.4

GitHub Security Advisory GHSA-cf42-v5r9-fg8j

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.23%

Top 33% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub