Advertisement






SQL-Injection in IP-TRACKING Mod for phpBB2.0.x

CVE Category Price Severity
N/A CWE-89 Not disclosed High
Author Risk Exploitation Type Date
Exploit Alert Team High Remote 2007-06-07
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2007050070

Below is a copy:

Information: The IP-Tracking Mod is a Extension for phpBB2.0.x which 
logs all Page hits the user of the Boards do including Referer, IP and 
Username. It contains a SQL-Injection on Admin-Level. You can get it 
from: 
http://www.phpbb.de/viewtopic.php?t=63690&postdays=0&postorder=asc&start
=0

Steps to reproduce: Go into your ACP, select under IP-Tracking 
IP-Search, select "no" at use wildcards and enter in Search Query what 
you want. It is direct passed through the Query. As Search Type I used IP.

PoC: enter
' UNION SELECT user_password as 
ip,user_id,username,user_active,user_regdate,user_level,user_posts from 
phpbb_users#
as Search-Query. This will display you all the hashed Userpasswords in IP

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum