CVE-2011-5204

Akiva WebBoard 8.x - Plaintext Password Storage

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-5204. PoCs published by Alexander Fuchs.

AI-analyzed exploit summary This writeup describes an SQL injection vulnerability in Akiva Webboard 8.x, allowing authentication bypass using 'admin'--' as both username and password, and discloses plaintext password retrieval from admin profiles.

Description

Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Alexander Fuchs · textwebappsphp
https://www.exploit-db.com/exploits/18293

This writeup describes an SQL injection vulnerability in Akiva Webboard 8.x, allowing authentication bypass using 'admin'--' as both username and password, and discloses plaintext password retrieval from admin profiles.

Classification
Writeup 90%
Attack Type
Sqli | Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Akiva Webboard 8.x
No auth needed
Prerequisites: access to login page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2011-12/0475.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47318
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18293

Scores

EPSS 0.0082
EPSS Percentile 52.5%

Details

CWE
CWE-255
Status published
Products (1)
akiva/webboard 8.0
Published Oct 04, 2012
Tracked Since Feb 18, 2026