7.5
CVSSv2

CVE-2006-6237

Published: 03/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote malicious users to execute arbitrary SQL commands via the threadvisit Cookie parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

woltlab burning board lite 1.0.2

Exploits

<?php print_r(' -------------------------------------------------------------------------------- Woltlab Burning Board Lite 102 decode_cookie() sql injection exploit by rgod retrog@aliceit site: retrogodaltervistaorg dork: "Powered by Burning Board Lite 102 * 2001-2004" -------------------------------------------------------------- ...