VieNuke VieBoard SQL Injection Vulnerability
BID:8967
Info
VieNuke VieBoard SQL Injection Vulnerability
| Bugtraq ID: | 8967 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2003 12:00AM |
| Updated: | Nov 03 2003 12:00AM |
| Credit: | This vulnerability was reported by <[email protected]>. |
| Vulnerable: |
VieNuke VieBoard 2.6 Beta 1 |
| Not Vulnerable: | |
Discussion
VieNuke VieBoard SQL Injection Vulnerability
It has been reported that VieNuke VieBoard may be prone to a SQL injection vulnerability that may allow an attacker to disclose sensitive information by supplying malicious SQL code to the underlying database.
A malicious user may influence database queries in order to view or modify sensitive information potentially compromising the software or the database.
It has been reported that VieNuke VieBoard may be prone to a SQL injection vulnerability that may allow an attacker to disclose sensitive information by supplying malicious SQL code to the underlying database.
A malicious user may influence database queries in order to view or modify sensitive information potentially compromising the software or the database.
Exploit / POC
VieNuke VieBoard SQL Injection Vulnerability
No exploit required. The following proof of concept has been provided.
http://www.example.com/vie/viewtopic.asp?forumid=48&id=2736'
No exploit required. The following proof of concept has been provided.
http://www.example.com/vie/viewtopic.asp?forumid=48&id=2736'
Solution / Fix
VieNuke VieBoard SQL Injection Vulnerability
Solution:
The vendor has released a patch to address this issue:
VieNuke VieBoard 2.6 Beta 1
Solution:
The vendor has released a patch to address this issue:
VieNuke VieBoard 2.6 Beta 1
-
VieNuke VieBoard_Patch.zip
http://www.vienuke.com/VieBoard_Patch.zip