Back

CVE-2005-2902

SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an uploaded file.

Published: Sep 14, 2005 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-vq56-x9hp-75c6

SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.35%

Top 31% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub