This exploit demonstrates a SQL injection vulnerability in rgboard 4.2.1 via the 'bbs_code' parameter in list.php. The PoC includes a crafted URL that extracts database and user information through a UNION-based SQL injection.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:rgboard 4.2.1
No auth needed
Prerequisites:Access to the target URL with the vulnerable parameter