Vikingboard 'register.php' SQL Column Truncation Unauthorized Access Vulnerability
BID:31408
Info
Vikingboard 'register.php' SQL Column Truncation Unauthorized Access Vulnerability
| Bugtraq ID: | 31408 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2008 12:00AM |
| Updated: | Sep 26 2008 04:39PM |
| Credit: | StAkeR |
| Vulnerable: |
Vikingboard Vikingboard 0.2 Beta Vikingboard Viking board 0.1.2 Vikingboard Viking board 0.1.1 Vikingboard Viking board 0.1b |
| Not Vulnerable: | |
Discussion
Vikingboard 'register.php' SQL Column Truncation Unauthorized Access Vulnerability
Vikingboard is prone to an unauthorized-access vulnerability.
Successfully exploiting this issue can allow attackers to register and log in as existing users.
Vikingboard 0.2 Beta is vulnerable; other versions may also be affected.
Vikingboard is prone to an unauthorized-access vulnerability.
Successfully exploiting this issue can allow attackers to register and log in as existing users.
Vikingboard 0.2 Beta is vulnerable; other versions may also be affected.
Exploit / POC
Vikingboard 'register.php' SQL Column Truncation Unauthorized Access Vulnerability
Attackers may exploit this issue via a browser.
The following example account registration data is available:
Username: [username][whitespace characters]NULL
Password: [password]
E-Mail: [E-Mail]
Attackers may exploit this issue via a browser.
The following example account registration data is available:
Username: [username][whitespace characters]NULL
Password: [password]
E-Mail: [E-Mail]
Solution / Fix
Vikingboard 'register.php' SQL Column Truncation Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Vikingboard 'register.php' SQL Column Truncation Unauthorized Access Vulnerability
References:
References:
- Vikingboard Homepage (Vikingboard)