Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3191. PoCs published by CWH Underground.
AI-analyzed exploit summary This is a writeup describing an arbitrary add-admin vulnerability in MFORUM 0.1a. The vulnerability allows privilege escalation by injecting code into user profile fields when magic_quotes_gpc is off.
Description
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.
Exploits (1)
This is a writeup describing an arbitrary add-admin vulnerability in MFORUM 0.1a. The vulnerability allows privilege escalation by injecting code into user profile fields when magic_quotes_gpc is off.