PHPBB DLMan Pro Module SQL Injection Vulnerability
BID:13028
Info
PHPBB DLMan Pro Module SQL Injection Vulnerability
| Bugtraq ID: | 13028 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1026 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 06 2005 12:00AM |
| Updated: | Mar 19 2015 08:33AM |
| Credit: | Discovery of this vulnerability is credited to LovER BOY. |
| Vulnerable: |
phpBB Group phpBB 2.0.13 phpBB Group phpBB 2.0.12 phpBB Group phpBB 2.0.11 phpBB Group phpBB 2.0.10 phpBB Group phpBB 2.0.9 phpBB Group phpBB 2.0.8 a phpBB Group phpBB 2.0.8 phpBB Group phpBB 2.0.7 a phpBB Group phpBB 2.0.7 phpBB Group phpBB 2.0.6 d phpBB Group phpBB 2.0.6 c phpBB Group phpBB 2.0.6 phpBB Group phpBB 2.0.5 phpBB Group phpBB 2.0.4 phpBB Group phpBB 2.0.3 phpBB Group phpBB 2.0.2 phpBB Group phpBB 2.0.1 phpBB Group phpBB 2.0 .0 DLMan Pro DLMan Pro 0.9.8 |
| Not Vulnerable: |
DLMan Pro DLMan Pro 0.9.8 |
Discussion
PHPBB DLMan Pro Module SQL Injection Vulnerability
The DLMan Pro mod for phpBB is reportedly affected by an SQL Injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
The DLMan Pro mod for phpBB is reportedly affected by an SQL Injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
PHPBB DLMan Pro Module SQL Injection Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com/[phpBB]/dlman.php?func=file_info&file_id='[SQL Injection]
No exploit is required.
The following proof of concept is available:
http://www.example.com/[phpBB]/dlman.php?func=file_info&file_id='[SQL Injection]
Solution / Fix
PHPBB DLMan Pro Module SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in DLMan Pro 0.9.8; please see the DLMan support forum for more information.
DLMan Pro DLMan Pro 0.9.8
Solution:
The vendor has addressed this issue in DLMan Pro 0.9.8; please see the DLMan support forum for more information.
DLMan Pro DLMan Pro 0.9.8
-
DLMan Pro DLMan Pro 0.9.8
http://www.snailsource.com/forum/dlman.php?sid=&func=select_folder&fol der_id=15