Invision Power Board Search.PHP "st" SQL Injection Vulnerability
BID:9766
Info
Invision Power Board Search.PHP "st" SQL Injection Vulnerability
| Bugtraq ID: | 9766 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0338 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovered by Knight Commander <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 2.0 PDR3 Invision Power Services Invision Board 2.0 Alpha 3 Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.2 Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Search.PHP "st" SQL Injection Vulnerability
It has been reported that an input validation error with the potential for use in a SQL injection attack is present in the "search.php" script. Consequently, malicious users may corrupt the resulting SQL queries (there are at least two) by specially crafting a value for the "st" variable. The impact of this vulnerability depends on the underlying database. It may be possible to corrupt/read sensitive data, execute commands/procedures on the database server or possibly exploit vulnerabilities in the database itself through this condition.
It has been reported that this issue may also affect the 'sources/Memberlist.php' and the 'sources/Online.php' scripts.
It has been reported that an input validation error with the potential for use in a SQL injection attack is present in the "search.php" script. Consequently, malicious users may corrupt the resulting SQL queries (there are at least two) by specially crafting a value for the "st" variable. The impact of this vulnerability depends on the underlying database. It may be possible to corrupt/read sensitive data, execute commands/procedures on the database server or possibly exploit vulnerabilities in the database itself through this condition.
It has been reported that this issue may also affect the 'sources/Memberlist.php' and the 'sources/Online.php' scripts.
Exploit / POC
Invision Power Board Search.PHP "st" SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Invision Power Board Search.PHP "st" SQL Injection Vulnerability
Solution:
The vendor has released a patch to address this issue in the search search.php script:
Invision Power Services Invision Board 1.0
Invision Power Services Invision Board 1.0.1
Invision Power Services Invision Board 1.1.1
Invision Power Services Invision Board 1.1.2
Invision Power Services Invision Board 1.2
Invision Power Services Invision Board 1.3
Invision Power Services Invision Board 2.0 PDR3
Invision Power Services Invision Board 2.0 Alpha 3
Solution:
The vendor has released a patch to address this issue in the search search.php script:
Invision Power Services Invision Board 1.0
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 1.0.1
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 1.1.1
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 1.1.2
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 1.2
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 1.3
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 2.0 PDR3
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
Invision Power Services Invision Board 2.0 Alpha 3
-
Invision Power Services search.zip
http://forums.invisionpower.com/index.php?s=bc4e9438d266206887560633dc e21d30&act=Attach&type=post&id=1298
References
Invision Power Board Search.PHP "st" SQL Injection Vulnerability
References:
References:
- Invision Power Board SQL injection! (Knight Commander
)