CVE-2005-3394
oaboard forum 1.0 - SQL Injection via Channel or Topic Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3394. PoCs published by [email protected].
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in OaBoard by injecting malicious SQL queries via the 'channel' and 'topic' parameters. It allows unauthorized data retrieval, such as passwords, from the underlying database.
Description
Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in OaBoard by injecting malicious SQL queries via the 'channel' and 'topic' parameters. It allows unauthorized data retrieval, such as passwords, from the underlying database.