7.5
CVSSv2

CVE-2013-3527

Published: 10/05/2013 Updated: 04/06/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Vanilla Forums prior to 2.0.18.8 allow remote malicious users to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vanillaforums vanilla 2.0.18.3

vanillaforums vanilla 2.0.18.1

vanillaforums vanilla 2.0.18

vanillaforums vanilla 2.0.17.4

vanillaforums vanilla 2.0.17.8

vanillaforums vanilla 2.0.17.9

vanillaforums vanilla 2.0.12

vanillaforums vanilla 2.0.11

vanillaforums vanilla 2.0.4

vanillaforums vanilla 2.0.3

vanillaforums vanilla

vanillaforums vanilla 2.0.18.6

vanillaforums vanilla 2.0.18.5

vanillaforums vanilla 2.0.18.4

vanillaforums vanilla 2.0.17

vanillaforums vanilla 2.0.17.10

vanillaforums vanilla 2.0.15

vanillaforums vanilla 2.0.14

vanillaforums vanilla 2.0.13

vanillaforums vanilla 2.0.6

vanillaforums vanilla 2.0.5

vanillaforums vanilla 2.0.17.3

vanillaforums vanilla 2.0.17.1

vanillaforums vanilla 2.0.16

vanillaforums vanilla 2.0.16.1

vanillaforums vanilla 2.0.8

vanillaforums vanilla 2.0.7

vanillaforums vanilla 2.0.17.5

vanillaforums vanilla 2.0.17.2

vanillaforums vanilla 2.0.17.6

vanillaforums vanilla 2.0.17.7

vanillaforums vanilla 2.0.10

vanillaforums vanilla 2.0.9

vanillaforums vanilla 2.0.2

vanillaforums vanilla 2.0.1

Exploits

# Exploit Title: Vanilla Forums - SQL-Injection - Insert arbitrary user & dump usertable # Date: 04/05/2013 # Exploit Author: bl4ckw0rm # Vendor Homepage: vanillaforumsorg/ # Version: 2-0-18-4 # Tested on: Windows Product Name: Vanilla Forums Vulnerable Version: Up to vanilla-core-2-0-18-4 Tested on: Windows Server 2003 Apache 24 ...