PAFileDB PAFileDB.PHP SQL Injection Vulnerability
BID:7183
Info
PAFileDB PAFileDB.PHP SQL Injection Vulnerability
| Bugtraq ID: | 7183 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2003 12:00AM |
| Updated: | Mar 24 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to flur <[email protected]>. |
| Vulnerable: |
PHP Arena paFileDB 3.1 PHP Arena paFileDB 3.0 Beta 3.1 PHP Arena paFileDB 3.0 |
| Not Vulnerable: | |
Discussion
PAFileDB PAFileDB.PHP SQL Injection Vulnerability
PHP Arenas' paFileDB has been reported prone to an SQL injection vulnerability.
This vulnerability is reportedly caused by a lack of sufficient sanitization of user-supplied URI parameters passed to paFileDB. As a result, an attacker may inject SQL instructions by supplying malicious commands embedded within requests to the affected paFileDB.php script.
PHP Arenas' paFileDB has been reported prone to an SQL injection vulnerability.
This vulnerability is reportedly caused by a lack of sufficient sanitization of user-supplied URI parameters passed to paFileDB. As a result, an attacker may inject SQL instructions by supplying malicious commands embedded within requests to the affected paFileDB.php script.