GNUboard 'ajax.autosave.php' Multiple SQL Injection Vulnerabilities
BID:66228
Info
GNUboard 'ajax.autosave.php' Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 66228 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2339 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2014 12:00AM |
| Updated: | Mar 19 2014 12:53AM |
| Credit: | Claepo Wang |
| Vulnerable: |
SIR GNUBoard 4.34.21 SIR GNUBoard 4.34.20 SIR GNUBoard 4.33.2 SIR GNUBoard 4.31.4 SIR GNUBoard 4.31.3 |
| Not Vulnerable: | |
Discussion
GNUboard 'ajax.autosave.php' Multiple SQL Injection Vulnerabilities
GNUboard is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
GNUboard is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
GNUboard 'ajax.autosave.php' Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. The following example URI is available:
http://www.example.com/bbs/ajax.autosave.php?content=1&subject=1[SQLi]
Attackers can use a browser to exploit these issues. The following example URI is available:
http://www.example.com/bbs/ajax.autosave.php?content=1&subject=1[SQLi]
Solution / Fix
GNUboard 'ajax.autosave.php' Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
GNUboard 'ajax.autosave.php' Multiple SQL Injection Vulnerabilities
References:
References:
- GNUBoard Homepage (SIR)