CVE-2012-5874

Elite-board Elite Bulletin Board < 2.1.21 - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f) register.php, (g) Search.php, (h) viewboard.php, or (i) viewtopic.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/23575

References (7)

Core 7
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/23575
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/88531
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-12/0114.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51622

Scores

EPSS 0.0119
EPSS Percentile 78.9%

Details

CWE
CWE-89
Status published
Products (26)
elite-board/elite_bulletin_board 2.0.0
elite-board/elite_bulletin_board 2.0.1
elite-board/elite_bulletin_board 2.0.2
elite-board/elite_bulletin_board 2.0.3
elite-board/elite_bulletin_board 2.1.0
elite-board/elite_bulletin_board 2.1.1
elite-board/elite_bulletin_board 2.1.2
elite-board/elite_bulletin_board 2.1.3
elite-board/elite_bulletin_board 2.1.4
elite-board/elite_bulletin_board 2.1.5
... and 16 more
Published Jan 12, 2013
Tracked Since Feb 18, 2026