My Little Forum Search.PHP SQL Injection Vulnerability
BID:14908
Info
My Little Forum Search.PHP SQL Injection Vulnerability
| Bugtraq ID: | 14908 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3045 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2005 12:00AM |
| Updated: | Feb 20 2007 04:06PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
my little homepage my little forum 1.5 my little homepage my little forum 1.3 |
| Not Vulnerable: | |
Discussion
My Little Forum Search.PHP SQL Injection Vulnerability
The 'my little forum' application is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
The 'my little forum' application is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
My Little Forum Search.PHP SQL Injection Vulnerability
No exploit is required.
The following proof of concept has been provided:
No exploit is required.
The following proof of concept has been provided:
Solution / Fix
My Little Forum Search.PHP SQL Injection Vulnerability
Solution:
Please see the references for more information.
Solution:
Please see the references for more information.
References
My Little Forum Search.PHP SQL Injection Vulnerability
References:
References:
- my little homepage (my little homepage)