UseBB Search SQL Injection Vulnerability
BID:14413
Info
UseBB Search SQL Injection Vulnerability
| Bugtraq ID: | 14413 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2005 12:00AM |
| Updated: | May 21 2005 12:00AM |
| Credit: | Stefan Esser <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
UseBB UseBB 0.5.1 |
| Not Vulnerable: |
UseBB UseBB 0.5.1 a |
Discussion
UseBB Search SQL Injection Vulnerability
UseBB is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
UseBB is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
UseBB Search SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
UseBB Search SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in UseBB version 0.5.1a and later:
UseBB UseBB 0.5.1
Solution:
The vendor has addressed this issue in UseBB version 0.5.1a and later:
UseBB UseBB 0.5.1
-
UseBB UseBB 0.5.1a
http://www.usebb.net/downloads/
References
UseBB Search SQL Injection Vulnerability
References:
References:
- UseBB Homepage (UseBB)
- Advisory 12/2005: UseBB Multiple Vulnerabilities (Hardened PHP Project)