CVE Database
/

CVE-2004-2340

Back to search

CVE-2004-2340

Published: Aug 16, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

** UNVERIFIABLE ** SQL injection vulnerability in PunkBuster Screenshot Database (PB-DB) Alpha 6 allows remote attackers to execute arbitrary SQL commands via the username and password fields of the login form. NOTE: the original vulnerability report contains several significant inconsistencies that make it unclear whether the report is accurate, including (1) PB-DB is really the "PunkBuster Screenshot Database" and not "PunkBuster" itself; (2) there is no apparent association between PunkBuster and "Punky Brewster"; (3) the claimed source code is not anywhere in Alpha 6.

VendorProductVersions

n/a

n/a

affected
n/a

References

9697
vdb-entry
x_refsource_BID
1009145
vdb-entry
x_refsource_SECTRACK
20040219 PunkBuster SQL Injection Attack
mailing-list
x_refsource_BUGTRAQ
18981
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now