IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
BID:15205
Info
IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
| Bugtraq ID: | 15205 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2005 12:00AM |
| Updated: | Oct 26 2005 12:00AM |
| Credit: | Discovery is credited to aLMaSTeR HaCKeR <[email protected]>. |
| Vulnerable: |
ipbProArcade ipbProArcade 2.5.2 |
| Not Vulnerable: | |
Discussion
IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
A remote SQL injection vulnerability reportedly affects ipbProArcade.
The problem affects the 'gameid' parameter.
An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.
A remote SQL injection vulnerability reportedly affects ipbProArcade.
The problem affects the 'gameid' parameter.
An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary database queries. This may facilitate the disclosure or corruption of sensitive database information.
Exploit / POC
IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
No exploit is required to leverage this issue.
The following proof of concept is available:
http://www.example.com/forums/index.php?act=Arcade&module=favorites&gameid=|aLMaSTeR
No exploit is required to leverage this issue.
The following proof of concept is available:
http://www.example.com/forums/index.php?act=Arcade&module=favorites&gameid=|aLMaSTeR
Solution / Fix
IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IPBProArcade GameID Parameter Remote SQL Injection Vulnerability
References:
References:
- ProArcade Home Page (ProArcade)