PHPNews News.PHP SQL Injection Vulnerability
BID:14133
Info
PHPNews News.PHP SQL Injection Vulnerability
| Bugtraq ID: | 14133 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2005 12:00AM |
| Updated: | Jul 04 2005 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
PHPNews PHPNews 1.2.5 |
| Not Vulnerable: |
PHPNews PHPNews 1.2.6 |
Discussion
PHPNews News.PHP SQL Injection Vulnerability
PHPNews is susceptible to an SQL injection vulnerability.
The problem occurs in the 'news.php' script of the affected application.
An attacker can exploit this issue to manipulate and inject SQL queries into the underlying database. It may be possible to leverage this issue to steal database contents including user credentials as well as to attack the underlying database.
Version 1.2.5 is reported susceptible to this vulnerability. Other versions may also be affected.
PHPNews is susceptible to an SQL injection vulnerability.
The problem occurs in the 'news.php' script of the affected application.
An attacker can exploit this issue to manipulate and inject SQL queries into the underlying database. It may be possible to leverage this issue to steal database contents including user credentials as well as to attack the underlying database.
Version 1.2.5 is reported susceptible to this vulnerability. Other versions may also be affected.
Exploit / POC
PHPNews News.PHP SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PHPNews News.PHP SQL Injection Vulnerability
Solution:
The vendor has released version 1.2.6 of the package to resolve this issue:
PHPNews PHPNews 1.2.5
Solution:
The vendor has released version 1.2.6 of the package to resolve this issue:
PHPNews PHPNews 1.2.5
-
PHPNews phpnews_1-2-6.zip
http://prdownloads.sourceforge.net/newsphp/phpnews_1-2-6.zip?download
References
PHPNews News.PHP SQL Injection Vulnerability
References:
References:
- PHPNews Home Page (PHPNews)
- Release Name: PHPNews 1.2.6 (PHPNews)