Beehive Forum Links.PHP Multiple Unspecified Cross-Site Scripting and SQL Injection Vulnerabilities
BID:26749
Info
Beehive Forum Links.PHP Multiple Unspecified Cross-Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 26749 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6241 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2007 12:00AM |
| Updated: | Dec 07 2007 06:32PM |
| Credit: | The vendor disclosed these these vulnerabilities. |
| Vulnerable: |
Beehive Forum Beehive Forum 0.7.1 Beehive Forum Beehive Forum 0.6.2 Beehive Forum Beehive Forum 0.6.1 Beehive Forum Beehive Forum 0.6 RC2 Beehive Forum Beehive Forum 0.6 RC1 |
| Not Vulnerable: |
Beehive Forum Beehive Forum 0.8 |
Discussion
Beehive Forum Links.PHP Multiple Unspecified Cross-Site Scripting and SQL Injection Vulnerabilities
Beehive Forum is prone to multiple unspecified cross-site scripting and SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Beehive Forum 0.7.1 is vulnerable; other versions may also be affected.
Beehive Forum is prone to multiple unspecified cross-site scripting and SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Beehive Forum 0.7.1 is vulnerable; other versions may also be affected.
Exploit / POC
Beehive Forum Links.PHP Multiple Unspecified Cross-Site Scripting and SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice a victim to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice a victim to follow a malicious URI.
Solution / Fix
Beehive Forum Links.PHP Multiple Unspecified Cross-Site Scripting and SQL Injection Vulnerabilities
Solution:
The vendor has released Beehive Forum 0.8 to address these issues. Please see the references for more information.
Beehive Forum Beehive Forum 0.6 RC2
Beehive Forum Beehive Forum 0.6 RC1
Beehive Forum Beehive Forum 0.6.1
Beehive Forum Beehive Forum 0.6.2
Beehive Forum Beehive Forum 0.7.1
Solution:
The vendor has released Beehive Forum 0.8 to address these issues. Please see the references for more information.
Beehive Forum Beehive Forum 0.6 RC2
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.6 RC1
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.6.1
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.6.2
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
Beehive Forum Beehive Forum 0.7.1
-
Beehive Forum beehiveforum08.tar.gz
http://downloads.sourceforge.net/beehiveforum/beehiveforum08.tar.gz?mo dtime=1196109842&big_mirror=0
References
Beehive Forum Links.PHP Multiple Unspecified Cross-Site Scripting and SQL Injection Vulnerabilities
References:
References:
- Beehive Forum 0.8 Release Notes (Beehive Forum)
- Open Classifieds Multiple Vulnerabilities (Moudi)