ttCMS / ttForum Index.PHP Instant-Messages Preferences SQL Injection Vulnerability
BID:7634
Info
ttCMS / ttForum Index.PHP Instant-Messages Preferences SQL Injection Vulnerability
| Bugtraq ID: | 7634 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2003 12:00AM |
| Updated: | May 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
ttForum ttForum 1.1 ttCMS ttCMS 2.3 ttCMS ttCMS 2.2 |
| Not Vulnerable: | |
Discussion
ttCMS / ttForum Index.PHP Instant-Messages Preferences SQL Injection Vulnerability
A problem with ttCMS/ttForum could make it possible for a remote user to launch SQL injection attacks.
It has been reported that a problem exists in the Instant-Messages script distributed as part of the software. Due to insufficient sanitizing of input, it is possible for a remote user to inject arbitrary SQL into the database used by the web forums.
It should be noted that the current version of YaBB SE, the Forum that ttForum was derived from, is not affected by this vulnerability.
A problem with ttCMS/ttForum could make it possible for a remote user to launch SQL injection attacks.
It has been reported that a problem exists in the Instant-Messages script distributed as part of the software. Due to insufficient sanitizing of input, it is possible for a remote user to inject arbitrary SQL into the database used by the web forums.
It should be noted that the current version of YaBB SE, the Forum that ttForum was derived from, is not affected by this vulnerability.
Exploit / POC
ttCMS / ttForum Index.PHP Instant-Messages Preferences SQL Injection Vulnerability
The following proof of concept was provided:
http://www.example.org/board/index.php?action=imprefs
Go to the Ignorelist-Textfield and enter:
',memberGroup='Administrator
The following proof of concept was provided:
http://www.example.org/board/index.php?action=imprefs
Go to the Ignorelist-Textfield and enter:
',memberGroup='Administrator
Solution / Fix
ttCMS / ttForum Index.PHP Instant-Messages Preferences SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ttCMS / ttForum Index.PHP Instant-Messages Preferences SQL Injection Vulnerability
References:
References:
- ttCMS (ttCMS)
- ttForum (ttForum)
- More vulnerabilities in ttForum/ttCMS -> SQL injection ([email protected])