Beehive Forum Post.PHP SQL Injection Vulnerability
BID:26492
Info
Beehive Forum Post.PHP SQL Injection Vulnerability
| Bugtraq ID: | 26492 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6014 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2007 12:00AM |
| Updated: | Dec 03 2007 11:33PM |
| Credit: | Nick Bennett and Robert Brown of Symantec are credited with the discovery of this vulnerability. |
| Vulnerable: |
Beehive Forum Beehive Forum 0.7.1 Beehive Forum Beehive Forum 0.6.2 Beehive Forum Beehive Forum 0.6.1 Beehive Forum Beehive Forum 0.6 RC2 Beehive Forum Beehive Forum 0.6 RC1 |
| Not Vulnerable: |
Beehive Forum Beehive Forum 0.8 |
Discussion
Beehive Forum Post.PHP SQL Injection Vulnerability
Beehive Forum is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Beehive Forum 0.7.1 and prior versions are vulnerable.
Beehive Forum is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Beehive Forum 0.7.1 and prior versions are vulnerable.
Exploit / POC
Beehive Forum Post.PHP SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Beehive Forum Post.PHP SQL Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Beehive Forum Beehive Forum 0.6 RC2
Beehive Forum Beehive Forum 0.6 RC1
Beehive Forum Beehive Forum 0.6.1
Beehive Forum Beehive Forum 0.6.2
Beehive Forum Beehive Forum 0.7.1
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Beehive Forum Beehive Forum 0.6 RC2
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.6 RC1
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.6.1
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.6.2
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.7.1
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
References
Beehive Forum Post.PHP SQL Injection Vulnerability
References:
References: