##################################################### # Woltlab Burning Board <= 2.2.2/2.3.3 modcp.php # SQL injection # Discovered by [R] ##################################################### Vendor: WoltLab URL: http://www.woltlab.de/ Version: <= 2.3.3 Type: SQL-injection Description: -------------------------------- The WoltLab Burning Board is a high customisable board software for every kind of use. SQL injection in modcp.php: -------------------------------- It's possible to execute malicious SQL code through modcp.php. But we need access to modcp.php. So, we must be a moderator or something like that. And here is the bug: /modcp.php?action=post_del&x='SQL_CODE_HERE /modcp.php?action=post_del&x=6&y='SQL_CODE_HERE Patch: -------------------------------- There isn't any patch from the vendor by now. Greetz & Visit: -------------------------------- Greetz to 2letterman, Lux2, Diabox, darkkilla, EaTh, redice Visit: http://rootbox.cx.la/ // 08.20.2005 // written by [R]