Vulnerabilities > CVE-2007-1725 - SQL Injection vulnerability in Icebb 1.0Rc5

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
icebb
critical
exploit available

Summary

SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges. Successful exploitation allows an attacker to gain administrator privileges, but requires that "magic_quotes_gpc" is disabled.

Vulnerable Configurations

Part Description Count
Application
Icebb
1

Exploit-Db

  • descriptionIceBB 1.0-rc5 Remote Code Execution Exploit. CVE-2007-1725,CVE-2007-1726. Webapps exploit for php platform
    fileexploits/php/webapps/3581.pl
    idEDB-ID:3581
    last seen2016-01-31
    modified2007-03-26
    platformphp
    port
    published2007-03-26
    reporterHessam-x
    sourcehttps://www.exploit-db.com/download/3581/
    titleIceBB 1.0-rc5 - Remote Code Execution Exploit
    typewebapps
  • descriptionIceBB 1.0-rc5 Remote Create Admin Exploit. CVE-2007-1725. Webapps exploit for php platform
    fileexploits/php/webapps/3580.pl
    idEDB-ID:3580
    last seen2016-01-31
    modified2007-03-26
    platformphp
    port
    published2007-03-26
    reporterHessam-x
    sourcehttps://www.exploit-db.com/download/3580/
    titleIceBB 1.0-rc5 - Remote Create Admin Exploit
    typewebapps