7.5
CVSSv2

CVE-2008-4627

Published: 21/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote malicious users to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

rgallery rgallery plugin 1.09

Exploits

import sys, urllib2, re print "\n " print " \\#'#/ " print " (--) " print " -------------------oOO---(_)---OOo--------------------" print " | rGallery 109 (+-) Exploit by Five-Three-Nine |" print " | Using Blind SQL Injection in 'itemID' of ...