phpBB2 Gender Mod Remote SQL Injection Vulnerability
BID:5342
Info
phpBB2 Gender Mod Remote SQL Injection Vulnerability
| Bugtraq ID: | 5342 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2002 12:00AM |
| Updated: | Jul 29 2002 12:00AM |
| Credit: | Discovered by langtuhaohoa caothuvolam <[email protected]>. |
| Vulnerable: |
Niels Chr Rød. Denmark Gender Mod 1.1.3 |
| Not Vulnerable: | |
Discussion
phpBB2 Gender Mod Remote SQL Injection Vulnerability
phpBB2 is an open-source web forum application that is written in PHP and backended by a number of database products. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Gender Mod is a modification for phpBB2 which allows the association of a gender with a given user profile. A SQL injection vulnerability has been reported in this mod. A remote user may subvert the SQL statement used to update their user profile, possibly gaining administrative access to the system.
phpBB2 is an open-source web forum application that is written in PHP and backended by a number of database products. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Gender Mod is a modification for phpBB2 which allows the association of a gender with a given user profile. A SQL injection vulnerability has been reported in this mod. A remote user may subvert the SQL statement used to update their user profile, possibly gaining administrative access to the system.
Exploit / POC
phpBB2 Gender Mod Remote SQL Injection Vulnerability
langtuhaohoa caothuvolam <[email protected]> has suggested submitting the following value for the 'gender' CGI parameter:
"0, user_level = 1 "
langtuhaohoa caothuvolam <[email protected]> has suggested submitting the following value for the 'gender' CGI parameter:
"0, user_level = 1 "
Solution / Fix
phpBB2 Gender Mod Remote SQL Injection Vulnerability
Solution:
An unofficial source code patch has been provided by langtuhaohoa caothuvolam <[email protected]>. Details are available in the referenced BugTraq post.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
An unofficial source code patch has been provided by langtuhaohoa caothuvolam <[email protected]>. Details are available in the referenced BugTraq post.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
phpBB2 Gender Mod Remote SQL Injection Vulnerability
References:
References: