7.5
CVSSv2

CVE-2006-2569

Published: 24/05/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and previous versions, a module for Woltlab Burning Board, allows remote malicious users to execute arbitrary SQL commands via the cat parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

woltlab burning board 2.3.1

woltlab burning board 2.3.3

woltlab burning board 2.0_rc2

woltlab burning board 2.2.2

woltlab burning board 2.0_beta_5

woltlab burning board 2.0_rc1

woltlab burning board 2.0_beta_3

woltlab burning board 2.0_beta_4

woltlab burning board 2.3.4

4r linklist 4r linklist

Exploits

#!/usr/bin/perl use IO::Socket; print q{ ################################################################################ ## ## ## Woltlab Burning Board 234 <= "linksphp" SQL Injection Exploit ## ## - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ...