7.5
CVSSv2

CVE-2006-4632

Published: 08/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote malicious users to execute arbitrary SQL commands via the (1) groupe parameter in addmembre.php and the (2) select parameter in moveto.php.

Vulnerable Product Search on Vulmon Subscribe to Product

softbb softbb

Exploits

#!/usr/bin/perl # # Affectedscr: SoftBB 01 # PocID: 11060904 # Type: PHP code execution, SQL Injection, Full Path Disclosure # Risklevel: High # VendorStatus: Unpatched # Srcdownload: softbbbe # Poclink: acid-rootnewfr/poc/11060904txt # Advisorylink: acid-rootnewfr/advisories/10060904txt # Credits ...