7.5
CVSSv2

CVE-2009-1947

Published: 05/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote malicious users to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.

Vulnerable Product Search on Vulmon Subscribe to Product

newsboard unclassified newsboard 1.6.4

Exploits

# Author_ girex # Homepage_ girexaltervistaorg # Date_ 31/05/2009 # CMS_ Unclassified NewsBoard 164 (and maybe lower) # Dork_ "This board is powered by the Unclassified NewsBoard software, 164" # Multiple remote vulnerabilities # 1) Remote SQL Injection (phpini regardless) # 2) Logs File Disclosure (register_globals = On) # 3) ...