6.8
CVSSv2

CVE-2008-2029

Published: 30/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote malicious users to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

minibb minibb

Exploits

# Author: __GiReX__ # Homepage: girexaltervistaorg # Date: 21/04/2008 # CMS: miniBB 22 (and maybe prior) # Site: minibbnet # Bug 1: Full Path Disclosure # Bug 2: Cross Site Scripting # Bug 3: Remote SQL Injection # Need: register_globals = On --------------------------------------- # 21/04/2008 Vendor informed # 22/04/2008 miniBB 22a ...