7.5
CVSSv2

CVE-2006-4279

Published: 21/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the icon_topic parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

xennobb xennobb 2.2.1

xennobb xennobb 2.1

xennobb xennobb 2.2

xennobb xennobb 1.0.5

xennobb xennobb 1.0.6

Exploits

source: wwwsecurityfocuscom/bid/19606/info XennoBB is prone to an SQL-injection vulnerability that could allow an attacker to influence the structure or logic of SQL queries made by the application --------------------- EXPLOIT --------------------- Submit a forged POST request to topic_postphp?action=post&fid={forum ID here} Wi ...