7.5
CVSSv2

CVE-2009-2311

Published: 02/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote malicious users to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than CVE-2008-4627.

Vulnerable Product Search on Vulmon Subscribe to Product

selbstzweck rgallery_plugin 1.2.3

Exploits

#!/usr/bin/perl -w use strict; use LWP::Simple; $| = 1; print q { ############################# ## WBB3 Blind SQL-Injector ## #### Exploit in rGallery #### ###### by Invisibility ###### ############################# \\\ Special greetz to # // Katharsis/**/nobody # \\\ Gunner/**/Cheese # // Thx ;) # ######### ...