Back to Database
Status published
High
CVE-2014-10029
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and...
Vulnerability Description
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-10029
Credits & Attribution
No credits recorded in the NVD database.
References
- http://fluxbb.org/forums/viewtopic.php?id=8001
- http://packetstormsecurity.com/files/129225/FluxBB-1.5.6-SQL-Injection.html
- http://secunia.com/advisories/59038
- http://seclists.org/fulldisclosure/2014/Nov/73
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98890
- https://fluxbb.org/development/core/tickets/990/
More from fluxbb
View All →CVE-2021-43677
Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS)...
Medium
6.1
CVE-2020-35240
FluxBB 1.5.11 is affected by cross-site scripting (XSS in the...
Medium
4.8
CVE-2020-28873
Fluxbb 1.5.11 is affected by a denial of service (DoS)...
High
7.5
CVE-2014-9574
Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows...
Critical
9.3
CVE-2014-10030
Open redirect vulnerability in forums/login.php in FluxBB before 1.4.13 and...
Medium
5.8
Affected Vendor
fluxbb
View all reports →Affected Software
fluxbb
Vulnerable Versions:
0, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.5.6
Timeline
Official Publish:
January 13th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.