CVE-2011-5090 Information
Feb 14, 2021
cve
Description
GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions which allows remote attackers to modify or delete data via a request to (1) mod_rewrite.php (2) comment_write_ok.php (3) poll/index.php (4) update/index.php (5) trackback.php or (6) an arbitrary poll.php script under theme/.
Reference
http://sirini.net/grboard/board.php?id=developer&articleNo=591 https://exchange.xforce.ibmcloud.com/vulnerabilities/75856
Share on: