VersatileBulletinBoard Multiple SQL Injection Vulnerabilities
BID:15068
Info
VersatileBulletinBoard Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 15068 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2005 12:00AM |
| Updated: | Oct 11 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
versatileBulletinBoard versatileBulletinBoard 1.0 .0.RC2 |
| Not Vulnerable: | |
Discussion
VersatileBulletinBoard Multiple SQL Injection Vulnerabilities
versatileBulletinBoard is prone to multiple SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
It should be noted that 'magic_quotes_gpc' must be set to 'off' for these vulnerabilities to be exploitable.
versatileBulletinBoard is prone to multiple SQL injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
It should be noted that 'magic_quotes_gpc' must be set to 'off' for these vulnerabilities to be exploitable.
Exploit / POC
VersatileBulletinBoard Multiple SQL Injection Vulnerabilities
Sample exploit code has been provided by the discoverer of these vulnerabilities.
Sample exploit code has been provided by the discoverer of these vulnerabilities.
Solution / Fix
VersatileBulletinBoard Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
VersatileBulletinBoard Multiple SQL Injection Vulnerabilities
References:
References:
- versatileBulletinBoard 1.00 RC2 poc exploit tool (rgod)
- versatileBulletinBoard Web Site (versatileBulletinBoard)
- versatileBulletinBoard V1.0.0 RC2 multiple SQL injection vulnerabilities (rgod)