CVE-2005-3870
edmobbs < 0.9 - SQL Injection via table or messageID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3870. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in edmoBBS due to unsanitized user input in the 'messageID' and 'table' parameters. It includes example URLs demonstrating the injection points but lacks executable exploit code.
Description
Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.
Exploits (1)
The provided text describes SQL injection vulnerabilities in edmoBBS due to unsanitized user input in the 'messageID' and 'table' parameters. It includes example URLs demonstrating the injection points but lacks executable exploit code.