CVE-2010-2133

Mylittleforum MY Little Forum - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Easy Laster · textwebappsphp
https://www.exploit-db.com/exploits/11616

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56618
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38485
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/11616

Scores

EPSS 0.0031
EPSS Percentile 54.5%

Details

CWE
CWE-89
Status published
Products (10)
mylittleforum/my_little_forum 1.7.6
mylittleforum/my_little_forum 2.0.2
mylittleforum/my_little_forum 2.1.1
mylittleforum/my_little_forum 2.1.2
mylittleforum/my_little_forum 2.1.3
mylittleforum/my_little_forum 2.1.4
mylittleforum/my_little_forum 2.2
mylittleforum/my_little_forum 2.2.1
mylittleforum/my_little_forum 2.2.2
mylittleforum/my_little_forum 2.2.3
Published Jun 02, 2010
Tracked Since Feb 18, 2026