Woltlab Info-DB Info_db.PHP Multiple SQL Injection Vulnerabilities
BID:15214
Info
Woltlab Info-DB Info_db.PHP Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 15214 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3369 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2005 12:00AM |
| Updated: | Jul 06 2007 03:37PM |
| Credit: | [email protected] is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Woltlab Burning Board 2.7 Woltlab Burning Board 2.6 Woltlab Burning Board 2.5 Woltlab Burning Board 2.4 Woltlab Burning Board 2.3.3 Woltlab Burning Board 2.3.1 Woltlab Burning Board 2.2.2 Woltlab Burning Board 2.0 RC2 Woltlab Burning Board 2.0 RC1 Woltlab Burning Board 2.0 beta 5 Woltlab Burning Board 2.0 beta 4 Woltlab Burning Board 2.0 beta 3 Woltlab Burning Board 1.1.1 Info-DB Info-DB |
| Not Vulnerable: | |
Discussion
Woltlab Info-DB Info_db.PHP Multiple SQL Injection Vulnerabilities
Info-DB is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Info-DB is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Exploit / POC
Woltlab Info-DB Info_db.PHP Multiple SQL Injection Vulnerabilities
No exploit is required.
Example URIs have been provided:
http://www.example.com/info_db.php?action=file&fileid=[SQL-Injection]
http://www.example.com/info_db.php?action=file&fileid=59&subkatid=[SQL-injection]
An exploit is available.
No exploit is required.
Example URIs have been provided:
http://www.example.com/info_db.php?action=file&fileid=[SQL-Injection]
http://www.example.com/info_db.php?action=file&fileid=59&subkatid=[SQL-injection]
An exploit is available.
Solution / Fix
Woltlab Info-DB Info_db.PHP Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Woltlab Info-DB Info_db.PHP Multiple SQL Injection Vulnerabilities
References:
References:
- CityForFree Product Page (CityForFree)
- Info-DB Web Site (Info-DB)
- Woltlab Burning Board info_db.php multiple SQL injection ([email protected])