Vulnerabilities > CVE-2006-3994 - Unspecified vulnerability in XMB Software XMB Forum

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
xmb-software
exploit available

Summary

SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.

Vulnerable Configurations

Part Description Count
Application
Xmb_Software
1

Exploit-Db

descriptionXMB <= 1.9.6 (u2uid) Remote SQL Injection Exploit (mq=off). CVE-2006-3994. Webapps exploit for php platform
fileexploits/php/webapps/2105.php
idEDB-ID:2105
last seen2016-01-31
modified2006-08-01
platformphp
port
published2006-08-01
reporterrgod
sourcehttps://www.exploit-db.com/download/2105/
titleXMB <= 1.9.6 u2uid Remote SQL Injection Exploit mq=off
typewebapps

Statements

contributor
lastmodified2008-12-11
organizationXMB
statementXMB versions 1.9.8 and later were checked and are not vulnerable.