7.5
CVSSv2

CVE-2007-3584

Published: 05/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and previous versions for Postnuke allows remote malicious users to execute arbitrary SQL commands via the order parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

postnuke software foundation pnphpbb2

Exploits

/* [i] PNphpBB2 "viewforumphp" SQL Injection Blind Password Hash Fishing Exploit [i] Vulnerable versions: PNphpBB2 <= 12i (current last version) [i] Bug discovered by: Coloss [i] Exploit by: Coloss [i] Date: 03072007 [Notes] [->] You need at least 2 posts in the forum [->] Thanks to waraxe for exploit structure I have saved much t ...