7.5
CVSSv2

CVE-2008-3601

Published: 12/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote malicious users to execute arbitrary SQL commands via the forums array parameter in a search action.

Vulnerable Product Search on Vulmon Subscribe to Product

quicksilver forums quicksilver forums 1.4.1

Exploits

<?php /* vuln: Quicksilver Forums 141 (forums[]) Remote SQL Injection Exploit download: wwwquicksilverforumscom/ author: irk4z[at]yahoopl homepage: irk4zwordpresscom/ greets: all friends ;) this is PoC exploit */ $host = $argv[1]; $path = $argv[2]; $prefix = "qsf_"; // this is default prefix echo "\n Q ...