7.5
CVSSv2

CVE-2007-1292

Published: 07/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin prior to 3.5.8, and prior to 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to achieve."

Vulnerable Product Search on Vulmon Subscribe to Product

jelsoft vbulletin 3.6.0

jelsoft vbulletin 3.6.5

jelsoft vbulletin

jelsoft vbulletin 3.6.1

jelsoft vbulletin 3.6.2

jelsoft vbulletin 3.6.3

jelsoft vbulletin 3.6.4

Exploits

<?php print_r(' ----------------------------------------------------------------------------- vBulletin <= 364 inlinemodphp "postids" sql injection / privilege escalation by session hijacking exploit by rgod mail: retrog at alice dot it site: retrogodaltervistaorg Works regardless of phpini settings, you need a Super Moderator a ...