CVE-2008-5577
scssboard 1.0-1.12 - Remote Code Execution via index.php inc_function Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5577. PoCs published by Inphex.
AI-analyzed exploit summary This Ruby script demonstrates SQL injection vulnerabilities in sCssBoard forum software by exploiting unsanitized input in various SQL queries. It includes proof-of-concept code for blind SQL injection and other SQL-based attacks.
Description
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.
Exploits (1)
This Ruby script demonstrates SQL injection vulnerabilities in sCssBoard forum software by exploiting unsanitized input in various SQL queries. It includes proof-of-concept code for blind SQL injection and other SQL-based attacks.