vBulletin SQL Injection Vulnerability
BID:11193
Info
vBulletin SQL Injection Vulnerability
| Bugtraq ID: | 11193 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2004 12:00AM |
| Updated: | Sep 15 2004 12:00AM |
| Credit: | al3ndaleeb disclosed this vulnerability. |
| Vulnerable: |
VBulletin VBulletin 3.0.3 VBulletin VBulletin 3.0.2 VBulletin VBulletin 3.0.1 VBulletin VBulletin 3.0 Gamma VBulletin VBulletin 3.0 beta 7 VBulletin VBulletin 3.0 beta 6 VBulletin VBulletin 3.0 beta 5 VBulletin VBulletin 3.0 beta 4 VBulletin VBulletin 3.0 beta 3 VBulletin VBulletin 3.0 beta 2 VBulletin VBulletin 3.0 Samba ppp 2.4.1 |
| Not Vulnerable: | |
Discussion
vBulletin SQL Injection Vulnerability
vBulletin is reported vulnerable to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.
An attacker may exploit this issue to manipulate and inject SQL queries onto the underlying database. It will be possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to make attacks against the underlying database.
Versions 3.0 through to 3.0.3 are reportedly affected by this issue.
vBulletin is reported vulnerable to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.
An attacker may exploit this issue to manipulate and inject SQL queries onto the underlying database. It will be possible to leverage this issue to steal database contents including administrator password hashes and user credentials as well as to make attacks against the underlying database.
Versions 3.0 through to 3.0.3 are reportedly affected by this issue.
Exploit / POC
vBulletin SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
vBulletin SQL Injection Vulnerability
Solution:
A vendor supplied fix is available. This file, 'authorize.php' is designed to replace the vulnerable 'authorize.php' script. The fix can be applied to vBulletin version 3.0.3 only, users are recommended to update to vBulletin version 3.0.3 before applying the fix:
Solution:
A vendor supplied fix is available. This file, 'authorize.php' is designed to replace the vulnerable 'authorize.php' script. The fix can be applied to vBulletin version 3.0.3 only, users are recommended to update to vBulletin version 3.0.3 before applying the fix:
References
vBulletin SQL Injection Vulnerability
References:
References:
- vBulletin "x_invoice_num" SQL Injection Vulnerability (Secunia)
- Vendor Homepage (Kyberna)