7.5
CVSSv2

CVE-2005-2323

Published: 19/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote malicious users to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.

Vulnerable Product Search on Vulmon Subscribe to Product

clever copy clever copy

class-1 class-1 forum 0.24.4

class-1 class-1 forum 0.23.2

Exploits

#!/usr/bin/perl -w # phpMyFamily Exploit injection # ============================== $banner = "phpMyFamily Exploit injection \n\n============================== \n\nINFGPG-Hacking&Security Research"; # # Greats: AresU (1st IndoSec Team),ADZ Security Team (has discovered bugs) # Info: 98to/infamous use IO::Socket; if ($#ARGV<0){ print "\n$b ...