7.5
CVSSv2

CVE-2007-1518

Published: 20/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote malicious users to execute arbitrary SQL commands via the array index of the applicationids array.

Vulnerable Product Search on Vulmon Subscribe to Product

woltlab burning board 2.0

woltlab burning board 2.0.3

woltlab burning board 2.1.6

woltlab burning board 2.2.1

woltlab burning board 2.3.5

woltlab burning board 2.3.6

woltlab burning board 2.0_beta_5

woltlab burning board 2.0_rc1

woltlab burning board 2.3.0

woltlab burning board 2.3.1

woltlab burning board 2.6

woltlab burning board 2.7

woltlab burning board 2.0_beta_3

woltlab burning board 2.0_beta_4

woltlab burning board 2.2.2

woltlab burning board 2.2.3

woltlab burning board 2.4

woltlab burning board 2.5

woltlab burning board 2.0_rc2

woltlab burning board 2.1.5

woltlab burning board 2.3.2

woltlab burning board 2.3.3

woltlab burning board 2.3.4

Exploits

#!/usr/bin/perl # Woltlab Burning Board 2X usergroupsphp SQL Injection exploit - burned2pl # written by x666 <blueshisha@safe-mailnet> # jmp-espkicks-assnet;blueshishachillsit # SR-CREW # should work on every wbb regardless of php settings # # use strict; use warnings; use LWP::UserAgent; use HTTP::Response; ...