6.5
CVSSv2

CVE-2008-3035

Published: 07/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and previous versions allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

xchangeboard xchangeboard

Exploits

###################### # # xchangeboard 170 final and lower # # ###################### # #Bug by: haZl0oh # #Dork: "Powered by xchangeboard" #info:you have to be an registered user to use it like this !!!! #there should be a lot more vulns there ;) # # # # credentials like passwords are saved as cookies :D ## ### ## # #PoC: ...