7.5
CVSSv2

CVE-2008-6970

Published: 13/08/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the Forum[] array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ubbcentral ubb.threads 6.0.2

ubbcentral ubb.threads 6.0.3

ubbcentral ubb.threads 6.3.1

ubbcentral ubb.threads 6.3

ubbcentral ubb.threads 6.5.1

ubbcentral ubb.threads 6.5

ubbcentral ubb.threads 7.2

ubbcentral ubb.threads

ubbcentral ubb.threads 5.0

ubbcentral ubb.threads 5.5.1

ubbcentral ubb.threads 6.2

ubbcentral ubb.threads 6.2.1

ubbcentral ubb.threads 6.4.3

ubbcentral ubb.threads 6.4.2

ubbcentral ubb.threads 6.4.1

ubbcentral ubb.threads 6.5.2_beta2

ubbcentral ubb.threads 6.5.2

ubbcentral ubb.threads 6.0

ubbcentral ubb.threads 6.0.1

ubbcentral ubb.threads 6.2.3

ubbcentral ubb.threads 6.2.2

ubbcentral ubb.threads 6.4.4

ubbcentral ubb.threads 6.5.3

ubbcentral ubb.threads 3.4

ubbcentral ubb.threads 3.5

ubbcentral ubb.threads 6.1

ubbcentral ubb.threads 6.1.1

ubbcentral ubb.threads 6.4

ubbcentral ubb.threads 6.5.1.1

ubbcentral ubb.threads 7.0

ubbcentral ubb.threads 7.1

Exploits

source: wwwsecurityfocuscom/bid/31074/info UBBthreads is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underl ...

Github Repositories

Blind SQL injection brute force.

DESCRIPTION Exploits PHP parameter input validation flaw and blindly brute force stored MD5 SQL hash for given user ID FILE CVE-2008-6970sh - Shell code program SOURCE githubcom/KyomaHooin/CVE-2008-6970