vendor:
Quicksilver Forums
by:
irk4z
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Quicksilver Forums
Affected Version From: 1.4.2001
Affected Version To: 1.4.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:quicksilver_forums:quicksilver_forums
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Quicksilver Forums 1.4.1 (forums[]) Remote SQL Injection Exploit
This is a proof-of-concept exploit for a remote SQL injection vulnerability in Quicksilver Forums 1.4.1. The exploit sends a malicious POST request to the vulnerable application, which then returns the username and password of the first user in the database. The exploit is written in PHP and requires the host and path of the vulnerable application as parameters.
Mitigation:
Upgrade to the latest version of Quicksilver Forums.