CVE-2012-4686
vBulletin 4.1.10 - SQL Injection via Announcement ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4686. PoCs published by Am!r.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in vBulletin 4.1.10, where insufficient sanitization of user-supplied data in the 'announcementid' parameter allows for SQLi attacks. No actual exploit code is present, only a description and a sample URL.
Description
SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in vBulletin 4.1.10, where insufficient sanitization of user-supplied data in the 'announcementid' parameter allows for SQLi attacks. No actual exploit code is present, only a description and a sample URL.