CVE-2011-5203
Akiva WebBoard < 8.0 - SQL Injection via WB/Default.asp Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5203. PoCs published by Alexander Fuchs.
AI-analyzed exploit summary This writeup describes an SQL injection vulnerability in Akiva Webboard 8.x, allowing authentication bypass using 'admin'--' as both username and password, and discloses plaintext password retrieval from admin profiles.
Description
SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This writeup describes an SQL injection vulnerability in Akiva Webboard 8.x, allowing authentication bypass using 'admin'--' as both username and password, and discloses plaintext password retrieval from admin profiles.