CVE Database · CVE-2008-3035
CVSS v3.1
N/A
EPSS
0.90%
Published
Jul 7, 2008
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.
Weaknesses (CWE)
Affected Products (1)
References (8)