Record summary

CVE-2009-2311 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than CVE-2008-4627.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWBB3 rGallery 1.2.3 - 'UserGallery' Blind SQL InjectionExploitDB exploitby InvisibilityNot analyzed1 file
ExploitDB

PoC details

References

4