vendor:
burning book
by:
ShAnKaR
7,5
CVSS
HIGH
SQL and PHP injection
89
CWE
Product Name: burning book
Affected Version From: <=1.1.2
Affected Version To: <=1.1.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
woltlab.de burning book <=1.1.2 SQL and PHP injection PoC
This PoC exploits a SQL and PHP injection vulnerability in woltlab.de burning book version <=1.1.2. The vulnerability is triggered when a maliciously crafted input is sent to the 'addentry.php' script. This can allow an attacker to execute arbitrary SQL and PHP code on the vulnerable system.
Mitigation:
Upgrade to the latest version of woltlab.de burning book.