7.5
CVSSv2

CVE-2005-4619

Published: 31/12/2005 Updated: 20/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and previous versions allows remote malicious users to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.

Vulnerable Product Search on Vulmon Subscribe to Product

phpoutsourcing zorum 3.2

phpoutsourcing zorum 3.3

phpoutsourcing zorum 3.4

phpoutsourcing zorum 3.5

phpoutsourcing zorum 3.0

phpoutsourcing zorum 3.1

Exploits

#!/usr/bin/perl use LWP::UserAgent; # ------------------------------------------------------------------------------------------- # Zorum forum (zorumphpoutsourcingcom/) version 35 sql injection exploit # by 1dtw0lf // RusH security team # *** work on all mysql versions # ---------------------------------------------------------------- ...