CVE-2002-1505

WoltLab Burning Board <2.0 RC 1 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1505. PoCs published by Cano2.

AI-analyzed exploit summary The exploit describes a SQL injection vulnerability in WoltLab's board.php script due to insufficient parameter sanitization. It allows attackers to modify SQL queries via the query string, potentially leading to privilege escalation or database corruption.

Description

SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Cano2 · textwebappsphp
https://www.exploit-db.com/exploits/21779

The exploit describes a SQL injection vulnerability in WoltLab's board.php script due to insufficient parameter sanitization. It allows attackers to modify SQL queries via the query string, potentially leading to privilege escalation or database corruption.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: WoltLab (version not specified)
No auth needed
Prerequisites: Access to the target web application · Knowledge of a valid user ID (e.g., admin ID)
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-09/0083.html
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10069.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5675

Scores

EPSS 0.0242
EPSS Percentile 82.5%

Details

Status published
Products (4)
woltlab/burning_board 2.0_beta_3
woltlab/burning_board 2.0_beta_4
woltlab/burning_board 2.0_beta_5
woltlab/burning_board < 2.0_rc1
Published Apr 02, 2003
Tracked Since Feb 18, 2026