6.8
CVSSv2

CVE-2010-1859

Published: 07/05/2010 Updated: 10/05/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.05

deluxebb deluxebb 1.0

deluxebb deluxebb

deluxebb deluxebb 1.2

deluxebb deluxebb 1.1

deluxebb deluxebb 1.08

deluxebb deluxebb 1.06

deluxebb deluxebb 1.09

deluxebb deluxebb 1.07

Exploits

source: wwwsecurityfocuscom/bid/39962/info DeluxeBB is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlyin ...