CVE-2005-3686

Unclassified NewsBoard < 1.5.3_patch3 - SQL Injection via DateFrom or DateUntil Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-3686. PoCs published by rgod.

AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in Unclassified NewsBoard 1.5.3 patch level 3 via the 'Datefrom' parameter. It allows an attacker to dump the admin MD5 password hash by leveraging time-based blind SQL injection techniques.

Description

SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1319

This PHP script exploits a blind SQL injection vulnerability in Unclassified NewsBoard 1.5.3 patch level 3 via the 'Datefrom' parameter. It allows an attacker to dump the admin MD5 password hash by leveraging time-based blind SQL injection techniques.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Unclassified NewsBoard 1.5.3 patch level 3
No auth needed
Prerequisites: Target must be running Unclassified NewsBoard 1.5.3pl3 · PHP environment with socket support or fsockopen enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20951
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2487
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.org/0511-exploits/unb153pl3_xpl.html
Various Sources x_refsource_misc
http://rgod.altervista.org/unb153pl3_xpl.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15466
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17614

Scores

EPSS 0.0129
EPSS Percentile 66.5%

Details

CWE
CWE-89
Status published
Products (1)
newsboard/unclassified_newsboard < 1.5.3_patch3
Published Nov 19, 2005
Tracked Since Feb 18, 2026