PHPBB 'bb_memberlist.php' Remote SQL Query Manipulation Vulnerability
BID:3411
Info
PHPBB 'bb_memberlist.php' Remote SQL Query Manipulation Vulnerability
| Bugtraq ID: | 3411 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2001 12:00AM |
| Updated: | Oct 08 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on October 8th, 2001 by Konrad Rieck <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 1.4.2 |
| Not Vulnerable: | |
Discussion
PHPBB 'bb_memberlist.php' Remote SQL Query Manipulation Vulnerability
phpBB is free, open-source forums software that is written in PHP and backended by MySQL.
A vulnerability exists in phpBB which makes it possible for a malicious user to remotely manipulate the logic of SQL queries. As a result, it may be possible for attackers to force malicious database operations.
phpBB is free, open-source forums software that is written in PHP and backended by MySQL.
A vulnerability exists in phpBB which makes it possible for a malicious user to remotely manipulate the logic of SQL queries. As a result, it may be possible for attackers to force malicious database operations.
Exploit / POC
PHPBB 'bb_memberlist.php' Remote SQL Query Manipulation Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
PHPBB 'bb_memberlist.php' Remote SQL Query Manipulation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPBB 'bb_memberlist.php' Remote SQL Query Manipulation Vulnerability
References:
References:
- phpBB Homepage (phpBB)