Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1350. PoCs published by TurkishWarriorr.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in phpBB's knowledge base module to extract user credentials from the database. The payload uses a UNION-based SQLi to concatenate user_id, username, and password fields.
Description
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action.
Exploits (1)
This exploit leverages a SQL injection vulnerability in phpBB's knowledge base module to extract user credentials from the database. The payload uses a UNION-based SQLi to concatenate user_id, username, and password fields.