CVE-2011-5091
grboard 1.8.6.5 - SQL Injection via tableType, blindTarget, delTargets[0], or isReported Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in GR Board (aka grboard) 1.8.6.5 Community Edition allow remote attackers to execute arbitrary SQL commands via the (1) tableType or (2) blindTarget parameter to view.php, (3) the delTargets[0] parameter to view_memo.php, or (4) the isReported parameter to write_ok.php.
References (2)
Core 2
Core References
Exploit, URL Repurposed x_refsource_confirm
http://sirini.net/grboard/board.php?id=developer&articleNo=591
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75855
Scores
EPSS
0.0120
EPSS Percentile
65.0%
Details
CWE
CWE-89
Status
published
Products (1)
grboard/grboard
1.8.6.5
Published
May 24, 2012
Tracked Since
Feb 18, 2026