Vulnerabilities > CVE-2002-2176 - Remote SQL Injection vulnerability in phpBB2 Gender Mod

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
phpbb-group
critical
exploit available

Summary

SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.

Vulnerable Configurations

Part Description Count
Application
Phpbb_Group
2

Exploit-Db

descriptionphpBB2 Gender Mod 1.1.3 Remote SQL Injection Vulnerability. CVE-2002-2176. Webapps exploit for php platform
idEDB-ID:21660
last seen2016-02-02
modified2002-07-29
published2002-07-29
reporterlangtuhaohoa caothuvolam
sourcehttps://www.exploit-db.com/download/21660/
titlephpBB2 Gender Mod 1.1.3 - Remote SQL Injection Vulnerability