CVE-2008-6632

Mercuryboard < 1.1.5 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).

Exploits (1)

exploitdb WORKING POC VERIFIED
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/5653

Scores

EPSS 0.0032
EPSS Percentile 55.3%

Details

CWE
CWE-89
Status published
Products (5)
mercuryboard/mercuryboard 1.0
mercuryboard/mercuryboard 1.1
mercuryboard/mercuryboard 1.1.1
mercuryboard/mercuryboard 1.1.2
mercuryboard/mercuryboard < 1.1.5
Published Apr 07, 2009
Tracked Since Feb 18, 2026