AntiBoard Unspecified SQL Injection Vulnerability
BID:11613
Info
AntiBoard Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 11613 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2004 12:00AM |
| Updated: | Nov 05 2004 12:00AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; Positive Technologies disclosed this issue. |
| Vulnerable: |
AntiBoard AntiBoard 0.7.3 |
| Not Vulnerable: | |
Discussion
AntiBoard Unspecified SQL Injection Vulnerability
An unspecified SQL injection vulnerability reportedly affects AntiBoard. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
An unspecified SQL injection vulnerability reportedly affects AntiBoard. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
AntiBoard Unspecified SQL Injection Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
AntiBoard Unspecified SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.