Vulnerabilities > CVE-2007-1254 - SQL-Injection vulnerability in Connectix Boards

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
connectix
exploit available

Summary

SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.

Exploit-Db

descriptionConnectix Boards <= 0.7 (p_skin) Multiple Vulnerabilities Exploit. CVE-2007-1254,CVE-2007-1255. Webapps exploit for php platform
fileexploits/php/webapps/3352.php
idEDB-ID:3352
last seen2016-01-31
modified2007-02-21
platformphp
port
published2007-02-21
reporterDarkFig
sourcehttps://www.exploit-db.com/download/3352/
titleConnectix Boards <= 0.7 p_skin Multiple Vulnerabilities Exploit
typewebapps