Back

CVE-2005-4702

SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, the demonstration code as used by third parties suggests that this might be a different type of vulnerability related to shell metacharacters. Finally, this could be a rediscovery of CVE-2004-1430.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
ipbproarcade ipbproarcade 2.5.2

GitHub Security Advisory GHSA-8r5x-26x3-9q3c

SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.03%

Top 39% most likely to be exploited

Threat Score 25.9 / 100

Data Sources

NVD EPSS GitHub