Lokwa BB Multiple SQL Injection Vulnerabilities
BID:4981
Info
Lokwa BB Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 4981 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jun 10 2002 12:00AM |
| Credit: | Discovered by Frog Man <[email protected]>. |
| Vulnerable: |
Lokwa Lokwa BB 1.2.1 |
| Not Vulnerable: | |
Discussion
Lokwa BB Multiple SQL Injection Vulnerabilities
Lokwa BB is a freely available message board forum. Versions of Lokwa are subject to SQL injection attacks.
Lokwa BB does not properly validate externally-supplied input when including arbitrary characters and additional SQL statements in an SQL query. As a result, attackers may be able to modify SQL queries performed by the application. The disclosure of sensitive information may be possible.
Under some circumstances, reports indicate that it may be possible to access and reply to arbitrary private messages.
This issue has been reported in the 'member.php', 'misc.php' and 'pm.php' scripts.
Lokwa BB is a freely available message board forum. Versions of Lokwa are subject to SQL injection attacks.
Lokwa BB does not properly validate externally-supplied input when including arbitrary characters and additional SQL statements in an SQL query. As a result, attackers may be able to modify SQL queries performed by the application. The disclosure of sensitive information may be possible.
Under some circumstances, reports indicate that it may be possible to access and reply to arbitrary private messages.
This issue has been reported in the 'member.php', 'misc.php' and 'pm.php' scripts.
Exploit / POC
Lokwa BB Multiple SQL Injection Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.