vendor:
Zorum forum
by:
1dt.w0lf // RusH security team
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Zorum forum
Affected Version From: 3.5
Affected Version To: 3.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2005
Zorum forum version 3.5 SQL injection exploit
This is a Perl script that exploits a SQL injection vulnerability in Zorum forum version 3.5. It allows an attacker to retrieve the username and password of a user by brute forcing the password hash.
Mitigation:
Upgrade to a patched version of Zorum forum