Phorum Read.PHP SQL Injection Vulnerability
BID:14095
Info
Phorum Read.PHP SQL Injection Vulnerability
| Bugtraq ID: | 14095 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2004 12:00AM |
| Updated: | Oct 24 2004 12:00AM |
| Credit: | The vulnerability was discovered by Positive Technologies. |
| Vulnerable: |
Phorum Phorum 5.0.11 |
| Not Vulnerable: |
Phorum Phorum 5.0.12 |
Discussion
Phorum Read.PHP SQL Injection Vulnerability
Phoroum is prone to SQL injection attacks. Insufficient sanitization of user input may allow a malicious user to manipulate the structure and logic of database queries.
Successful exploitation could allow the attacker to compromise security properties of the application and the database. Possible consequences include unauthorized access to the application and database.
This issue has been reported to exist in Phorum 5.0.11. Earlier versions may also be affected.
Phoroum is prone to SQL injection attacks. Insufficient sanitization of user input may allow a malicious user to manipulate the structure and logic of database queries.
Successful exploitation could allow the attacker to compromise security properties of the application and the database. Possible consequences include unauthorized access to the application and database.
This issue has been reported to exist in Phorum 5.0.11. Earlier versions may also be affected.
Exploit / POC
Phorum Read.PHP SQL Injection Vulnerability
The following example sufficient to exploit this vulnerability is provided:
http://www.example.com/read.php?1,[MALICIOUS_SQL_CODE],newer
The following example sufficient to exploit this vulnerability is provided:
http://www.example.com/read.php?1,[MALICIOUS_SQL_CODE],newer
Solution / Fix
Phorum Read.PHP SQL Injection Vulnerability
Solution:
Users may upgrade to version 5.0.12 or higher.
Phorum Phorum 5.0.11
Solution:
Users may upgrade to version 5.0.12 or higher.
Phorum Phorum 5.0.11
-
Phorum phorum-5.0.16.tar.gz
http://phorum.org/downloads/phorum-5.0.16.tar.gz
References
Phorum Read.PHP SQL Injection Vulnerability
References:
References:
- Positive Technologies Advisory Page (Positive Technologies)
- Release: phorum.5.0.12 (Phorum )