CVE-2011-5091

grboard 1.8.6.5 - SQL Injection via tableType, blindTarget, delTargets[0], or isReported Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in GR Board (aka grboard) 1.8.6.5 Community Edition allow remote attackers to execute arbitrary SQL commands via the (1) tableType or (2) blindTarget parameter to view.php, (3) the delTargets[0] parameter to view_memo.php, or (4) the isReported parameter to write_ok.php.

References (2)

Core 2
Core References
Exploit, URL Repurposed x_refsource_confirm
http://sirini.net/grboard/board.php?id=developer&articleNo=591
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75855

Scores

EPSS 0.0120
EPSS Percentile 65.0%

Details

CWE
CWE-89
Status published
Products (1)
grboard/grboard 1.8.6.5
Published May 24, 2012
Tracked Since Feb 18, 2026