Advertisement






WordPress Plugin KBoard 2.7 - SQL Injection

CVE Category Price Severity
CVE-2020-24918 CWE-89 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2016-10-01
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2016100005

Below is a copy:

WordPress Plugin KBoard 2.7 - SQL Injection######################
# Exploit Title : WordPress Plugin KBoard 2.7 - SQL Injection 
# Exploit Author :  Persian Hack Team
# Homepage : http://persian-team.ir
# Google Dork : intitle:"KBoard 2.7"
# Vendor Homepage : http://www.cosmosfarm.com/products/kboard
# Category [ Webapps ]
# Tested on [ Win ]
# Version : 2.7
# Date 2016/09/26
######################
#
# PoC
#    => Sql Injection :
# uid Parameter Vulnerable To SQL
# Demo :
# http://www.site.com/wp-content/plugins/kboard/board.php?pageid=1&board_id=1&mod=document&uid=[Inject Here]
# Video : http://persian-team.ir/showthread.php?tid=162
######################
# Discovered by :  FireKernel & T3NZOG4N & Mojtaba MobhaM 
# B3li3v3 M3 I will n3v3r St0p
# Greetz : Dr.Askarzade & Masood Ostad & Dr.Koorangi &  Milad Hacking & JOK3R $ Mr_Mask_Black And All Persian Hack Team Members
######################


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum