CVE-2016-6195
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.
- Affected products
- Vbulletin
- Vbulletin
- ≤ 4.2.2, 4.2.3
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 68.5% (99th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2016-08-30
CVE-2016-6195 at NVD
7 known exploits for CVE-2016-6195
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Argument Injection in Phpmailer_Project Phpmailer
vBulletin 4 ForumRunner SQL Injection
vBulletin 4.2.3 - SQL Injection Vulnerability
vBulletin 4.2.3 SQL Injection
vBulletin /forumrunner/request.php SQL injection vulnerability
vBulletin 3.6.0 4.2.3 - ForumRunner SQL Injection
vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection