DeluxeBB SQL Injection And PHP Injection Vulnerabilities
BID:29062
Info
DeluxeBB SQL Injection And PHP Injection Vulnerabilities
| Bugtraq ID: | 29062 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2195 CVE-2008-2194 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | EgiX |
| Vulnerable: |
DeluxeBB DeluxeBB 1.2 DeluxeBB DeluxeBB 1.1 DeluxeBB DeluxeBB 1.09 DeluxeBB DeluxeBB 1.08 DeluxeBB DeluxeBB 1.07 DeluxeBB DeluxeBB 1.06 |
| Not Vulnerable: | |
Discussion
DeluxeBB SQL Injection And PHP Injection Vulnerabilities
DeluxeBB is prone to an SQL-injection vulnerability and a PHP-injection vulnerability.
Attackers can exploit these issues to execute arbitrary script code in the context of the webserver, compromise the application, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect DeluxeBB 1.2 and prior versions.
DeluxeBB is prone to an SQL-injection vulnerability and a PHP-injection vulnerability.
Attackers can exploit these issues to execute arbitrary script code in the context of the webserver, compromise the application, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect DeluxeBB 1.2 and prior versions.
Exploit / POC
DeluxeBB SQL Injection And PHP Injection Vulnerabilities
Attackers can exploit these issues via a browser.
The following proof-of-concept information is available:
Attackers can exploit these issues via a browser.
The following proof-of-concept information is available:
Solution / Fix
DeluxeBB SQL Injection And PHP Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: %[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: %[email protected].