CVE-2008-1939 – W1L3D4 philboard 1.0 - 'philboard_reply.asp' SQL Injection
https://notcve.org/view.php?id=CVE-2008-1939
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to (b) philboard_newtopic.asp, different vectors than CVE-2007-2641 and CVE-2007-0920. Múltiples Vulnerabilidades de Inyección SQL en W1L3D4 Philboard 1.0, permiten a atacantes remotos ejecutar comandos SQL arbitrariamente a través de los parámetros (1) id y (2) topic en (a) philboard_reply.asp y del parámetro (3) forumid en (b) philboard_newtopic.asp, vectores diferentes de CVE-2007-2641 y CVE-2007-0920. • https://www.exploit-db.com/exploits/5475 http://www.securityfocus.com/bid/28871 http://www.vupen.com/english/advisories/2008/1340/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41957 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2007-0920 – philboard 1.14 - 'philboard_forum.asp' SQL Injection
https://notcve.org/view.php?id=CVE-2007-0920
SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter. Vulnerabilidad de inyección SQL en philboard_forum.asp en Philboard 1.14 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro forumid. • https://www.exploit-db.com/exploits/3295 http://osvdb.org/35678 http://www.securityfocus.com/bid/22532 http://www.vupen.com/english/advisories/2007/0600 https://exchange.xforce.ibmcloud.com/vulnerabilities/32442 •