CVE-2008-5863

Woltlab Burning Board 3.0 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parameter in a get_user action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by katharsis · perlwebappsphp
https://www.exploit-db.com/exploits/7530

Scores

EPSS 0.0041
EPSS Percentile 61.6%

Details

CWE
CWE-89
Status published
Products (1)
v-gn/userlocator 3.0
Published Jan 06, 2009
Tracked Since Feb 18, 2026