CVE-2008-5576
scssboard 1.0-1.12 - Unauthenticated Authentication Bypass via current_user[users_level] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5576. PoCs published by Inphex.
AI-analyzed exploit summary This Ruby script demonstrates SQL injection vulnerabilities in sCssBoard forum software by exploiting unsanitized input in various SQL queries. It includes proof-of-concept code for blind SQL injection and other SQL-based attacks.
Description
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
Exploits (1)
This Ruby script demonstrates SQL injection vulnerabilities in sCssBoard forum software by exploiting unsanitized input in various SQL queries. It includes proof-of-concept code for blind SQL injection and other SQL-based attacks.