20020909 phpGB: DoS and executing_arbitrary_commandsmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-09/0076.html CVE-2002-1482
phpGB 1.x - SQL Injection
Record summary
CVE-2002-1482 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBphpGB 1.x - SQL InjectionExploitDB exploitby ppp-designNot analyzed1 file
References
4phpgb-login-sql-injection(10068)vdb entry
http://www.iss.net/security_center/static/10068.php 5673vdb entry
http://www.securityfocus.com/bid/5673 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1482