Description
SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Product(s):
- Ideal Science IdealBB 1.4.9
- Ideal Science IdealBB 1.4.9 Beta
- Ideal Science IdealBB 1.4.9a
- Ideal Science IdealBB 1.5.1
- Ideal Science IdealBB 1.5.2
- Ideal Science IdealBB 1.5.2a
- Ideal Science IdealBB 1.5.2c
- Ideal Science IdealBB 1.5.3
- Ideal Science IdealBB 1.5 Beta 1
- Ideal Science IdealBB 1.5 Beta 2
- Ideal Science IdealBB 1.5 Beta 3
- Ideal Science IdealBB 1.5 Beta 4
- Ideal Science IdealBB 1.5 Beta 5
- Ideal Science IdealBB 1.5 RC1
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-2209, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-2209 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.