MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
BID:15204
Info
MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
| Bugtraq ID: | 15204 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2005 12:00AM |
| Updated: | Oct 26 2005 12:00AM |
| Credit: | Animal <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
MyBulletinBoard MyBulletinBoard 1.0 PR2 MyBulletinBoard MyBulletinBoard RC4 |
| Not Vulnerable: | |
Discussion
MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
MyBulletinBoard is prone to an SQL injection vulnerability.
This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. Reports indicate that an attacker can gain administrative access by exploiting this issue.
MyBulletinBoard is prone to an SQL injection vulnerability.
This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. Reports indicate that an attacker can gain administrative access by exploiting this issue.
Exploit / POC
MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
No exploit is required.
The following proof of concept is available:
No exploit is required.
The following proof of concept is available:
Solution / Fix
MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
Solution:
The vendor has released a patch addressing this and other issues:
MyBulletinBoard MyBulletinBoard RC4
MyBulletinBoard MyBulletinBoard 1.0 PR2
Solution:
The vendor has released a patch addressing this and other issues:
MyBulletinBoard MyBulletinBoard RC4
-
MyBulletinBoard MyBB PR2 Patch
http://community.mybboard.net/attachment.php?aid=1505
MyBulletinBoard MyBulletinBoard 1.0 PR2
-
MyBulletinBoard MyBB PR2 Patch
http://community.mybboard.net/attachment.php?aid=1505
References
MyBulletinBoard Usercp.PHP SQL Injection Vulnerability
References:
References:
- MyBB PR2 Security Update (MyBulletinBoard)
- MyBulletinBoard Home Page (MyBulletinBoard)
- SQL-Injection in MyBulletinBoard allows attacker to become a board admin. (Animal
)