Vulnerabilities > CVE-2006-2740 - Input Validation vulnerability in tinyBB

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
epic-designs
exploit available

Summary

Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors. Successful exploitation requires that "magic_quotes_gpc" is disabled.

Vulnerable Configurations

Part Description Count
Application
Epic_Designs
1

Exploit-Db

descriptiontinyBB <= 0.3 Remote (Include / SQL Injection) Vulnerabilities. CVE-2006-2739,CVE-2006-2740. Webapps exploit for php platform
idEDB-ID:1839
last seen2016-01-31
modified2006-05-28
published2006-05-28
reporternukedx
sourcehttps://www.exploit-db.com/download/1839/
titletinyBB <= 0.3 - Remote Include / SQL Injection Vulnerabilities