7.5
CVSSv2

CVE-2011-4066

Published: 04/11/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and previous versions allows remote malicious users to execute arbitrary SQL commands via the PATH_INFO.

Vulnerable Product Search on Vulmon Subscribe to Product

sir gnuboard 3.38

sir gnuboard 3.37

sir gnuboard

sir gnuboard 4.31.03

sir gnuboard 3.34

sir gnuboard 3.33

sir gnuboard 3.32

sir gnuboard 3.40

sir gnuboard 3.39

sir gnuboard 3.31

sir gnuboard 3.30

sir gnuboard 3.36

sir gnuboard 3.35

Exploits

# Exploit Title: Gnuboard <= 43302 PATH_INFO SQL INJECTION Vulnerability # Google Dork: inurl:gnuboard4/bbs/boardphp # Date: 2011-2-14 # Author: flyh4t # Software Link: sircokr/main/gnuboard4/ # Version: Gnuboard <= 43302 # Tested on: linux+apache # CVE : CVE-2011-4066 Gnuboard <= 43302 PATH_INFO SQL INJECTION Vulnerabili ...
Gnuboard versions 43302 and below suffer from a remote SQL injection vulnerability in tpphp ...