31872Third-party advisory
http://secunia.com/advisories/31872 CVE-2008-4355
pForum 1.30 - 'showprofil.php' SQL Injection
Record summary
CVE-2008-4355 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBpForum 1.30 - 'showprofil.php' SQL InjectionExploitDB exploitby tmhNot analyzed1 file
References
631150vdb entry
http://www.securityfocus.com/bid/31150 ADV-2008-2559vdb entry
http://www.vupen.com/english/advisories/2008/2559 pforum-showprofil-sql-injection(45079)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45079 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4355 6442exploit
https://www.exploit-db.com/exploits/6442