CVE-2009-2311
rGallery plugin 1.2.3 for WoltLab Burning Board - SQL Injection via userID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2311. PoCs published by Invisibility.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in WoltLab Burning Board 3 (WBB3) via the rGallery module. It extracts user password hashes and salts by brute-forcing characters using ASCII values.
Description
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to execute arbitrary SQL commands via the userID parameter in the RGalleryUserGallery page to index.php, a different vector than CVE-2008-4627.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in WoltLab Burning Board 3 (WBB3) via the rGallery module. It extracts user password hashes and salts by brute-forcing characters using ASCII values.