Leszek Krupinski L-Forum Search Script SQL Injection Vulnerability
BID:5468
Info
Leszek Krupinski L-Forum Search Script SQL Injection Vulnerability
| Bugtraq ID: | 5468 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1457 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery of vulnerability credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
Leszek Krupinski L-Forum 2.4 .0 |
| Not Vulnerable: | |
Discussion
Leszek Krupinski L-Forum Search Script SQL Injection Vulnerability
Reportedly, L-Forum is vulnerable to SQL injection attacks. The vulnerability lies in the file 'search.php'
L-Forum does not properly sanitize user input that is used as part of the search parameter in the 'search.php' file. SQL code may be inserted into the requests and executed by the database server.
Reportedly, L-Forum is vulnerable to SQL injection attacks. The vulnerability lies in the file 'search.php'
L-Forum does not properly sanitize user input that is used as part of the search parameter in the 'search.php' file. SQL code may be inserted into the requests and executed by the database server.
Exploit / POC
Leszek Krupinski L-Forum Search Script SQL Injection Vulnerability
"Matthew Murphy" <[email protected]> has provided exploit information for Postgres and MySQL databases. This vulnerability may be exploited with a web browser.
Postgres:
http://localhost/search.php?search=a%27%20order%20by%20time%20desc%3b%20[query]
MySQL:
http://localhost/search.php?search=a%25%27%20order%20by%20time%20desc%3b%20[query]
"Matthew Murphy" <[email protected]> has provided exploit information for Postgres and MySQL databases. This vulnerability may be exploited with a web browser.
Postgres:
http://localhost/search.php?search=a%27%20order%20by%20time%20desc%3b%20[query]
MySQL:
http://localhost/search.php?search=a%25%27%20order%20by%20time%20desc%3b%20[query]
Solution / Fix
Leszek Krupinski L-Forum Search Script SQL Injection Vulnerability
Solution:
The following unofficial patch was provided by "Matthew Murphy" <[email protected]>. This patch has not been verified by us. Users who apply the following patch do so at their own risk.
http://sourceforge.net/tracker/download.php?group_id=53716&atid=471341&file_id=29026&aid=594867
Solution:
The following unofficial patch was provided by "Matthew Murphy" <[email protected]>. This patch has not been verified by us. Users who apply the following patch do so at their own risk.
http://sourceforge.net/tracker/download.php?group_id=53716&atid=471341&file_id=29026&aid=594867
References
Leszek Krupinski L-Forum Search Script SQL Injection Vulnerability
References:
References:
- L-Forum Home Page (Leszek Krupinski)