CVE-2007-3526

Buddy Zone < 1.5 - SQL Injection via News ID, Category ID, or Member ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3526. PoCs published by t0pP8uZz.

AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Buddy Zone Version 1.5 and prior. It provides multiple URLs with crafted SQL queries to extract admin and user credentials from the database.

Description

Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/4128

This exploit demonstrates SQL injection vulnerabilities in Buddy Zone Version 1.5 and prior. It provides multiple URLs with crafted SQL queries to extract admin and user credentials from the database.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Buddy Zone Social Networking Script Version 1.5 and prior
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4128
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38960
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35187
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24726
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38962
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38961

Scores

EPSS 0.0249
EPSS Percentile 82.6%

Details

Status published
Products (1)
vastal_i-tech/buddy_zone < 1.5
Published Jul 03, 2007
Tracked Since Feb 18, 2026