CVE-2008-3035
xchangeboard < 1.70 - Authenticated SQL Injection via newThread.php boardID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3035. PoCs published by haZl0oh.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in xchangeboard 1.70 and lower. It allows an authenticated user to extract sensitive user information, including email addresses and password hashes, via a crafted SQL query in the 'boardID' parameter.
Description
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in xchangeboard 1.70 and lower. It allows an authenticated user to extract sensitive user information, including email addresses and password hashes, via a crafted SQL query in the 'boardID' parameter.