CVE-2012-2908
Viscacha 0.8.1.1 - SQL Injection via bbcodeexample, buttonimage, or bbcodetag Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-2908. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary The exploit demonstrates SQL injection and persistent XSS vulnerabilities in Viscacha Forum CMS v0.8.1.1. The SQLi is exploitable via POST requests to the BBCode module, while the XSS vulnerabilities are present in multiple input fields such as private messages and comments.
Description
Multiple SQL injection vulnerabilities in admin/bbcodes.php in Viscacha 0.8.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) bbcodeexample, (2) buttonimage, or (3) bbcodetag parameter.
Exploits (1)
The exploit demonstrates SQL injection and persistent XSS vulnerabilities in Viscacha Forum CMS v0.8.1.1. The SQLi is exploitable via POST requests to the BBCode module, while the XSS vulnerabilities are present in multiple input fields such as private messages and comments.