CelerBB Information Disclosure and Multiple SQL Injection Vulnerabilities
BID:34014
Info
CelerBB Information Disclosure and Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 34014 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2009 12:00AM |
| Updated: | Mar 06 2009 07:46PM |
| Credit: | Salvatore "drosophila" Fresta |
| Vulnerable: |
CelerBB CelerBB 0.0.2 |
| Not Vulnerable: | |
Discussion
CelerBB Information Disclosure and Multiple SQL Injection Vulnerabilities
CelerBB is prone to an information-disclosure vulnerability and multiple SQL-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
A successful attack could allow an attacker to obtain sensitive information, compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
CelerBB 0.0.2 is vulnerable; other versions may also be affected.
CelerBB is prone to an information-disclosure vulnerability and multiple SQL-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
A successful attack could allow an attacker to obtain sensitive information, compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
CelerBB 0.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
CelerBB Information Disclosure and Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs and proof-of-concept code are available:
Attackers can use a browser to exploit these issues.
The following example URIs and proof-of-concept code are available:
Solution / Fix
CelerBB Information Disclosure and Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CelerBB Information Disclosure and Multiple SQL Injection Vulnerabilities
References:
References:
- CelerBB Homepage (CelerBB)
- CelerBB 0.0.2 Multiple Vulnerabilities ("Salvatore \"drosophila\" Fresta"
)