VBulletin SQL Query Manipulation Vulnerability
BID:4364
Info
VBulletin SQL Query Manipulation Vulnerability
| Bugtraq ID: | 4364 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2002 12:00AM |
| Updated: | Mar 10 2002 12:00AM |
| Credit: | Discovery of this issue is credited to the vBulletin development team. |
| Vulnerable: |
VBulletin VBulletin 2.2.3 |
| Not Vulnerable: |
VBulletin VBulletin 2.2.4 |
Discussion
VBulletin SQL Query Manipulation Vulnerability
vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems.
Affected versions of vBulletin do not sufficiently sanitize user-supplied input before it is used to construct a SQL query, making it prone to SQL query injection.
This issue only occurs when vBulletin has been configured to allow guest postings.
vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems.
Affected versions of vBulletin do not sufficiently sanitize user-supplied input before it is used to construct a SQL query, making it prone to SQL query injection.
This issue only occurs when vBulletin has been configured to allow guest postings.
Exploit / POC
VBulletin SQL Query Manipulation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
VBulletin SQL Query Manipulation Vulnerability
Solution:
This issue has been addressed in version 2.2.4. Users may find details on how to obtain an upgrade at the following link:
http://www.vbulletin.com/download/
Solution:
This issue has been addressed in version 2.2.4. Users may find details on how to obtain an upgrade at the following link:
http://www.vbulletin.com/download/
References
VBulletin SQL Query Manipulation Vulnerability
References:
References:
- vBulletin 2.2.4 Released (vBulletin)
- Vendor Homepage (Kyberna)