7.5
CVSSv2

CVE-2009-1033

Published: 20/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in misc.php in DeluxeBB 1.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.07

deluxebb deluxebb 1.1

deluxebb deluxebb 1.09

deluxebb deluxebb 1.2

deluxebb deluxebb 1.0

deluxebb deluxebb

deluxebb deluxebb 1.05

deluxebb deluxebb 1.06

deluxebb deluxebb 1.08

Exploits

# Author: girex # Homepage: girexaltervistaorg # Date: 18/03/2009 # CMS: DeluxeBB 13 and prior # site: deluxebbcom # NOTE: - Works regardless of phpini settings - This SQL injection will shows you username and md5 of ALL registered users of the site - This PoC was written for educational purpose Use it at your own risk ...