phpBB Fetch All SQL Injection Vulnerability
BID:10868
Info
phpBB Fetch All SQL Injection Vulnerability
| Bugtraq ID: | 10868 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2004 12:00AM |
| Updated: | Aug 04 2004 12:00AM |
| Credit: | This issue was disclosed in the product change log. |
| Vulnerable: |
Volker Rattel phpBB Fetch All 2.0.11 Volker Rattel phpBB Fetch All 2.0.10 |
| Not Vulnerable: |
Volker Rattel phpBB Fetch All 2.0.12 |
Discussion
phpBB Fetch All SQL Injection Vulnerability
It is reported that phpBB Fetch All is susceptible to an SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
The successful exploitation of this vulnerability depends on the implementation of the web application that includes phpBB Fetch All as a component. It may or may not be possible to effectively pass malicious SQL statements to the underlying function.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Versions prior to 2.0.12 are reported to be affected.
It is reported that phpBB Fetch All is susceptible to an SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
The successful exploitation of this vulnerability depends on the implementation of the web application that includes phpBB Fetch All as a component. It may or may not be possible to effectively pass malicious SQL statements to the underlying function.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Versions prior to 2.0.12 are reported to be affected.
Exploit / POC
phpBB Fetch All SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
phpBB Fetch All SQL Injection Vulnerability
Solution:
The vendor has released version 2.0.12 addressing this issue.
Volker Rattel phpBB Fetch All 2.0.10
Volker Rattel phpBB Fetch All 2.0.11
Solution:
The vendor has released version 2.0.12 addressing this issue.
Volker Rattel phpBB Fetch All 2.0.10
-
Volker Rattel phpbb_fetch_all-2.0.12.zip
http://prdownloads.sourceforge.net/phpbbfetchall/phpbb_fetch_all-2.0.1 2.zip?download
Volker Rattel phpBB Fetch All 2.0.11
-
Volker Rattel phpbb_fetch_all-2.0.12.zip
http://prdownloads.sourceforge.net/phpbbfetchall/phpbb_fetch_all-2.0.1 2.zip?download
References
phpBB Fetch All SQL Injection Vulnerability
References:
References:
- phpBB Fetch All Home Page (Volker Rattel)
- phpBB Homepage (phpBB)