10
CVSSv2

CVE-2002-1482

Published: 22/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in login.php for phpGB 1.20 and previous versions, when magic_quotes_gpc is not enabled, allows remote malicious users to gain administrative privileges via SQL code in the password entry.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgb phpgb 1.20

phpgb phpgb 1.10

phpgb phpgb 1.30

Exploits

source: wwwsecurityfocuscom/bid/5673/info phpGB is vulnerable to a SQL injection vulnerability The cause of the issue is that the bulletin board relies on the PHP magic_quotes_gpc directive to sanitize variables that are used in SQL queries If magic_quotes_gpc is not enabled, then it will be possible for attackers to mount SQL injecti ...