Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0768. PoCs published by darkjoker.
AI-analyzed exploit summary This exploit leverages a blind SQL injection vulnerability in YapBB <= 1.2 to extract user passwords by abusing the `forumhop.php` endpoint. It uses time-based techniques (BENCHMARK) to infer password characters one by one.
Description
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.
Exploits (1)
This exploit leverages a blind SQL injection vulnerability in YapBB <= 1.2 to extract user passwords by abusing the `forumhop.php` endpoint. It uses time-based techniques (BENCHMARK) to infer password characters one by one.