2 results (0.004 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2

24 Apr 2008 — Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to (b) philboard_newtopic.asp, different vectors than CVE-2007-2641 and CVE-2007-0920. Múltiples Vulnerabilidades de Inyección SQL en W1L3D4 Philboard 1.0, permiten a atacantes remotos ejecutar comandos SQL arbitrariamente a través de los parámetros (1) id y (2) topic en (a) philboard_reply.as... • https://www.exploit-db.com/exploits/5475 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2

14 Feb 2007 — SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter. Vulnerabilidad de inyección SQL en philboard_forum.asp en Philboard 1.14 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro forumid. • https://www.exploit-db.com/exploits/3295 •