Phorum Registration Script hide_email SQL Injection Vulnerability
BID:9363
Info
Phorum Registration Script hide_email SQL Injection Vulnerability
| Bugtraq ID: | 9363 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2004 12:00AM |
| Updated: | Jan 05 2004 12:00AM |
| Credit: | Discovery is credited to Calum Power. |
| Vulnerable: |
Phorum Phorum 3.4.5 Phorum Phorum 3.4.4 Phorum Phorum 3.4.3 Phorum Phorum 3.4.2 Phorum Phorum 3.4.1 Phorum Phorum 3.4 |
| Not Vulnerable: |
Phorum Phorum 3.4.6 |
Discussion
Phorum Registration Script hide_email SQL Injection Vulnerability
Phorum is prone to an SQL injection vulnerability. The registration script does not adequately filter SQL syntax from user-supplied input before including it in a database query. As a result, remote attackers may influence the logic and structure of database queries made by the software.
This vulnerability could potentially be exploited to compromise the bulletin board installation, disclose sensitive information from within the database or even to launch attacks against the database implementation.
Phorum is prone to an SQL injection vulnerability. The registration script does not adequately filter SQL syntax from user-supplied input before including it in a database query. As a result, remote attackers may influence the logic and structure of database queries made by the software.
This vulnerability could potentially be exploited to compromise the bulletin board installation, disclose sensitive information from within the database or even to launch attacks against the database implementation.
Exploit / POC
Phorum Registration Script hide_email SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Phorum Registration Script hide_email SQL Injection Vulnerability
Solution:
This issues has been addressed in Phorum version 3.4.6.
Phorum Phorum 3.4
Phorum Phorum 3.4.1
Phorum Phorum 3.4.2
Phorum Phorum 3.4.3
Phorum Phorum 3.4.4
Phorum Phorum 3.4.5
Solution:
This issues has been addressed in Phorum version 3.4.6.
Phorum Phorum 3.4
-
Phorum phorum-3.4.6.tar.gz
http://phorum.org/downloads/phorum-3.4.6.tar.gz
Phorum Phorum 3.4.1
-
Phorum phorum-3.4.6.tar.gz
http://phorum.org/downloads/phorum-3.4.6.tar.gz
Phorum Phorum 3.4.2
-
Phorum phorum-3.4.6.tar.gz
http://phorum.org/downloads/phorum-3.4.6.tar.gz
Phorum Phorum 3.4.3
-
Phorum phorum-3.4.6.tar.gz
http://phorum.org/downloads/phorum-3.4.6.tar.gz
Phorum Phorum 3.4.4
-
Phorum phorum-3.4.6.tar.gz
http://phorum.org/downloads/phorum-3.4.6.tar.gz
Phorum Phorum 3.4.5
-
Phorum phorum-3.4.6.tar.gz
http://phorum.org/downloads/phorum-3.4.6.tar.gz
References
Phorum Registration Script hide_email SQL Injection Vulnerability
References:
References:
- Phorum Homepage (Phorum)
- Multiple Vulnerabilities in Phorum 3.4.5 ("Calum Power"
)