CVE-2005-2673

WoltLab Burning Board <2.3.3 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2673. PoCs published by [R].

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Woltlab Burning Board, where unsanitized user input in the 'modcp.php' script allows attackers with moderator credentials to inject malicious SQL code. The exploit vectors are provided as URL examples.

Description

SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by [R] · textwebappsphp
https://www.exploit-db.com/exploits/26176

The provided text describes an SQL injection vulnerability in Woltlab Burning Board, where unsanitized user input in the 'modcp.php' script allows attackers with moderator credentials to inject malicious SQL code. The exploit vectors are provided as URL examples.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Woltlab Burning Board
Auth required
Prerequisites: moderator credentials
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014746
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14617

Scores

EPSS 0.0105
EPSS Percentile 60.9%

Details

Status published
Products (2)
woltlab/burning_board 2.2.2
woltlab/burning_board 2.2.3
Published Aug 23, 2005
Tracked Since Feb 18, 2026