CVE-2007-3052

PNphpBB2 < 1.2i - SQL Injection via Index.php c Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3052. PoCs published by Kacper.

AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in PNphpBB2 <= 1.2, allowing an attacker to extract admin credentials (username and password hash) from the database. It constructs a malicious SQL query via the 'c' parameter in the URL and retrieves the data by parsing the HTTP response.

Description

SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper · phpwebappsphp
https://www.exploit-db.com/exploits/4026

This exploit targets a SQL injection vulnerability in PNphpBB2 <= 1.2, allowing an attacker to extract admin credentials (username and password hash) from the database. It constructs a malicious SQL query via the 'c' parameter in the URL and retrieves the data by parsing the HTTP response.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PNphpBB2 <= 1.2
No auth needed
Prerequisites: Target server running PNphpBB2 <= 1.2 · Knowledge of the database prefix (optional) · User ID of the admin account (optional)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2037
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35424
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25480
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4026
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34668
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24295

Scores

EPSS 0.0251
EPSS Percentile 82.7%

Details

Status published
Products (1)
postnuke_software_foundation/pnphpbb < 1.2i
Published Jun 06, 2007
Tracked Since Feb 18, 2026