PoC Index

CVE-2010-4151

MEDIUM 6.8EPSS 1.2%

SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.18% chance of exploitation in the next 30 days, 66th percentile
Published
2010-11-03
Updated
2024-08-07

ExploitDB entries (1)

References

Related