7.5
CVSSv2

CVE-2008-3416

Published: 31/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in modules/members.php in IceBB prior to 1.0-rc9.3 allows remote malicious users to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.

Vulnerable Product Search on Vulmon Subscribe to Product

icebb icebb 1.0

Exploits

# Author: __GiReX__ 26/07/08 # Homepage: girexaltervistaorg # CMS: IceBB <= 10-RC92 # Site: icebbnet # Bug: Blind SQL Injection # Exploit: Session Hijacking PoC # Works regardless of phpini settings # Description: IceBB is a powerful, fast, free, and open-source forum solution powered by the free PHP and MySQL IceBB scales w ...