CVE-2010-1859

SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:deluxebb:deluxebb:*:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.0:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.1:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.2:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.05:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.06:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.07:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.08:*:*:*:*:*:*:*
cpe:2.3:a:deluxebb:deluxebb:1.09:*:*:*:*:*:*:*

History

21 Nov 2024, 01:15

Type Values Removed Values Added
References () http://php-security.org/2010/05/06/mops-2010-011-deluxebb-newthread-sql-injection-vulnerability/index.html - Exploit () http://php-security.org/2010/05/06/mops-2010-011-deluxebb-newthread-sql-injection-vulnerability/index.html - Exploit
References () http://www.securityfocus.com/bid/39962 - Exploit () http://www.securityfocus.com/bid/39962 - Exploit

Information

Published : 2010-05-07 23:00

Updated : 2024-11-21 01:15


NVD link : CVE-2010-1859

Mitre link : CVE-2010-1859

CVE.ORG link : CVE-2010-1859


JSON object : View

Products Affected

deluxebb

  • deluxebb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')