CVE-2005-3872
ugroup < 2.6.2 - SQL Injection via FORUM_ID or TOPIC_ID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3872. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in UGroup software, specifically in the topic.php file. It outlines vulnerable parameters (CAT_ID, FORUM_ID, TOPIC_ID) but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in Ugroup 2.6.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID parameter in forum.php, and the (2) TOPIC_ID, (3) FORUM_ID, and (4) CAT_ID parameters in topic.php.
Exploits (2)
The provided text describes SQL injection vulnerabilities in UGroup software, specifically in the topic.php file. It outlines vulnerable parameters (CAT_ID, FORUM_ID, TOPIC_ID) but does not include executable exploit code.
The provided text describes a SQL injection vulnerability in UGroup software, specifically in the forum.php file via the FORUM_ID parameter. It lacks executable exploit code but details the vulnerability and potential impact.