CVE-2012-4034

PBBoard 2.1.4 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4034. PoCs published by High-Tech Bridge.

AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in PBBoard 2.1.4, allowing unauthorized database access and potential arbitrary file upload. The PoC includes crafted HTTP forms targeting various endpoints with SQLi payloads.

Description

Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge · textwebappsphp
https://www.exploit-db.com/exploits/37614

This exploit demonstrates multiple SQL injection vulnerabilities in PBBoard 2.1.4, allowing unauthorized database access and potential arbitrary file upload. The PoC includes crafted HTTP forms targeting various endpoints with SQLi payloads.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: PBBoard 2.1.4
No auth needed
Prerequisites: Access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54916
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/77501
Vendor Advisory, URL Repurposed x_refsource_misc
http://www.pbboard.com/forums/t10353.html
URL Repurposed x_refsource_misc
http://www.pbboard.com/forums/t10352.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/84480
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50153

Scores

EPSS 0.0251
EPSS Percentile 82.7%

Details

CWE
CWE-89
Status published
Products (1)
pbboard/pbboard 2.1.4
Published Aug 12, 2012
Tracked Since Feb 18, 2026