5.1
CVSSv2

CVE-2008-6777

Published: 01/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.

Vulnerable Product Search on Vulmon Subscribe to Product

myphp myphp forum 1.0

myphp myphp forum 2.0

myphp myphp forum

Exploits

/* ----------------------------------------------------------------------------------- MyPHP Forum (Final) <= 30 (Edit Topics/Blind SQL Injection) Remote Vulnerabilities ----------------------------------------------------------------------------------- Discovered By StAkeR[at]hotmail[dot]it Download On wwwmyphpws/ ...