6.8
CVSSv2

CVE-2010-4151

Published: 03/11/2010 Updated: 14/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.05

deluxebb deluxebb 1.08

deluxebb deluxebb 1.2

deluxebb deluxebb 1.0

deluxebb deluxebb 1.07

deluxebb deluxebb

deluxebb deluxebb 1.09

deluxebb deluxebb 1.06

deluxebb deluxebb 1.1

Exploits

# Author: girex # Homepage: girexaltervistaorg # Date: 18/03/2009 # CMS: DeluxeBB 13 and prior # site: deluxebbcom # NOTE: - Works regardless of phpini settings - This SQL injection will shows you username and md5 of ALL registered users of the site - This PoC was written for educational purpose Use it at your own risk ...