Back

CVE-2005-3686

SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.

Published: Nov 19, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
newsboard unclassified_newsboard *

GitHub Security Advisory GHSA-qx4w-pmj5-w2pm

SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.29%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub