6.5
CVSSv2

CVE-2009-3052

Published: 03/09/2009 Updated: 19/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon prior to 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php.

Vulnerable Product Search on Vulmon Subscribe to Product

absoluteanime prime_quick_style 1.2.3

Exploits

########################################################################## # # phpBB3 addon prime_quick_style GetAdmin Exploit # # Vulnerability found and exploited by -SmoG- # # target file: prime_quick_stylephp # # # vuln: POST parameter "prime_quick_style" is injectable # source: wwwphpbbcom/community/viewtopicphp?f=70&t=6926 ...