PunBB Search.PHP SQL Injection Vulnerability
BID:15114
Info
PunBB Search.PHP SQL Injection Vulnerability
| Bugtraq ID: | 15114 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2005 12:00AM |
| Updated: | Oct 15 2005 12:00AM |
| Credit: | Devil_box of KAPDA is credited with the discovery of this vulnerability. |
| Vulnerable: |
PunBB PunBB 1.2.8 PunBB PunBB 1.2.7 PunBB PunBB 1.2.6 PunBB PunBB 1.2.5 PunBB PunBB 1.2.4 PunBB PunBB 1.2.3 PunBB PunBB 1.2.2 PunBB PunBB 1.2.1 |
| Not Vulnerable: |
PunBB PunBB 1.2.9 |
Discussion
PunBB Search.PHP SQL Injection Vulnerability
PunBB is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
PunBB is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
PunBB Search.PHP SQL Injection Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/search.php?action=search&keywords=&author=d3vilbox&forum=-1&search_in=all&sort_by=0&sort_dir=DESC&show_as=topics&search=Submit&old_searches[]=[sql-injection]
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/search.php?action=search&keywords=&author=d3vilbox&forum=-1&search_in=all&sort_by=0&sort_dir=DESC&show_as=topics&search=Submit&old_searches[]=[sql-injection]
Solution / Fix
PunBB Search.PHP SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in PunBB version 1.2.9:
PunBB PunBB 1.2.1
PunBB PunBB 1.2.2
PunBB PunBB 1.2.3
PunBB PunBB 1.2.4
PunBB PunBB 1.2.5
PunBB PunBB 1.2.6
PunBB PunBB 1.2.7
PunBB PunBB 1.2.8
Solution:
The vendor has addressed this issue in PunBB version 1.2.9:
PunBB PunBB 1.2.1
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.2
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.3
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.4
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.5
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.6
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.7
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
PunBB PunBB 1.2.8
-
PunBB punbb-1.2.9.tar.gz
http://www.punbb.org/download/punbb-1.2.9.tar.gz
References
PunBB Search.PHP SQL Injection Vulnerability
References:
References: