DeluxeBB CP.PHP SQL Injection Vulnerability
BID:18648
CVE-2006-3304 |Info
DeluxeBB CP.PHP SQL Injection Vulnerability
| Bugtraq ID: | 18648 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2006 12:00AM |
| Updated: | Jun 26 2006 07:25PM |
| Credit: | Hessam-x has been credited with the discovery of this vulnerability. |
| Vulnerable: |
DeluxeBB DeluxeBB 1.07 |
| Not Vulnerable: | |
Discussion
DeluxeBB CP.PHP SQL Injection Vulnerability
DeluxeBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
DeluxeBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Exploit / POC
DeluxeBB CP.PHP SQL Injection Vulnerability
This issue can be exploited through a web client.
The following proof-of-concept code is available:
This issue can be exploited through a web client.
The following proof-of-concept code is available:
Solution / Fix
DeluxeBB CP.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
DeluxeBB CP.PHP SQL Injection Vulnerability
References:
References:
- Blog:CMS Web Site (Blog:CMS)
- DeluxeBB <= 1.07 Create Admin Exploit (Hessam-x)