Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3589. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in b1gBB 2.24.0. The SQLi exploits retrieve user credentials via union-based injection, while the XSS exploit executes arbitrary JavaScript via a crafted user parameter.
Description
Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in b1gBB 2.24.0. The SQLi exploits retrieve user credentials via union-based injection, while the XSS exploit executes arbitrary JavaScript via a crafted user parameter.