IceBB SQL Injection Vulnerability
BID:30381
Info
IceBB SQL Injection Vulnerability
| Bugtraq ID: | 30381 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3416 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2008 12:00AM |
| Updated: | May 07 2015 05:25PM |
| Credit: | girex |
| Vulnerable: |
IceBB IceBB 1.0-rc9.2 IceBB IceBB 1.0-rc9.1 |
| Not Vulnerable: |
IceBB IceBB 1.0-rc9.3 |
Discussion
IceBB SQL Injection Vulnerability
IceBB is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to IceBB 1.0-rc9.3 are vulnerable.
IceBB is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to IceBB 1.0-rc9.3 are vulnerable.
Exploit / POC
IceBB SQL Injection Vulnerability
An attacker can exploit this issue via a browser.
The following exploit script is available:
An attacker can exploit this issue via a browser.
The following exploit script is available:
Solution / Fix
IceBB SQL Injection Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
IceBB SQL Injection Vulnerability
References:
References: