YaBB SE Profile.php SQL Injection Vulnerability
BID:18625
CVE-2006-3275 |Info
YaBB SE Profile.php SQL Injection Vulnerability
| Bugtraq ID: | 18625 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2006 12:00AM |
| Updated: | Jun 26 2006 04:20AM |
| Credit: | Sam Thomas has been credited for the discovery of this vulnerability. |
| Vulnerable: |
YaBB SE YaBB SE 1.5.5 |
| Not Vulnerable: | |
Discussion
YaBB SE Profile.php SQL Injection Vulnerability
YaBB SE is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well
YaBB SE is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well
Exploit / POC
YaBB SE Profile.php SQL Injection Vulnerability
This issue can be exploited through a web client.
The follow proof-of-concept URI is available:
This issue can be exploited through a web client.
The follow proof-of-concept URI is available:
Solution / Fix
YaBB SE Profile.php SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
YaBB SE Profile.php SQL Injection Vulnerability
References:
References:
- NDSD-06-001 (Sam Thomas)
- YaBB SE Home Page (YaBB )