Advertisement






Woltlab Burning Board info_db.php multiple SQL injection

CVE Category Price Severity
N/A CWE-89 N/A High
Author Risk Exploitation Type Date
N/A High Remote 2005-10-29
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.5 0.85

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2005100065

Below is a copy:

#################################################################
#
#   Woltlab Burning Board info_db.php multiple SQL      #   injection    
#
#################################################################
->discovered by [R]

Vendor: "Trooper"
URL:  www.wbbcoderforum.de
Version: <= 2.7
Type: SQL-injection

Description:
------------------------
Info-DB is a very powerful and popular download-module with many features.

Information:
------------------------
Info-DB is prone to multiple SQL injection vulnerabilities.
(It's possible to upload any files through info_db.php.)

Bug:
------------------------
[1] /info_db.php?action=file&fileid=[SQL-Injection]
[2] /info_db.php?action=file&fileid=59&subkatid=[SQL-injection]

Both tested on 2.5.
All other versions should be vulnerable, too.
An exploit-code is available at rootbox.cx.la/batznet.com

Patch:
------------------------
No Patch available.

Greetz:
------------------------
greetz fly out to 2lm, Lux2, redice, triple6, darkkilla, EaTh

// written by [R]
// www.batznet.com

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum