PHPBB Search.PHP Search_Results Parameter SQL Injection Vulnerability
BID:9883
Info
PHPBB Search.PHP Search_Results Parameter SQL Injection Vulnerability
| Bugtraq ID: | 9883 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2004 12:00AM |
| Updated: | Mar 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to pokleyzz <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 2.0.6 phpBB Group phpBB 2.0.5 phpBB Group phpBB 2.0.4 phpBB Group phpBB 2.0.3 phpBB Group phpBB 2.0.2 phpBB Group phpBB 2.0.1 phpBB Group phpBB 2.0 .0 phpBB Group phpBB 2.0 RC4 phpBB Group phpBB 2.0 RC3 phpBB Group phpBB 2.0 RC2 phpBB Group phpBB 2.0 RC1 phpBB Group phpBB 2.0 Beta 1 phpBB Group phpBB 1.4.4 phpBB Group phpBB 1.4.2 phpBB Group phpBB 1.4.1 phpBB Group phpBB 1.4 .0 phpBB Group phpBB 1.2.1 phpBB Group phpBB 1.2 .0 phpBB Group phpBB 1.0 .0 |
| Not Vulnerable: |
phpBB Group phpBB 2.0.8 |
Discussion
PHPBB Search.PHP Search_Results Parameter SQL Injection Vulnerability
A vulnerability has been reported to exist in the software that may allow a remote user to inject malicious SQL syntax into database queries. The problem reportedly exists in one of the parameters of the search.php script. This issue is caused by insufficient sanitization of user-supplied data. A remote attacker may exploit this issue to influence SQL query logic to disclose sensitive information that could be used to gain unauthorized access.
A vulnerability has been reported to exist in the software that may allow a remote user to inject malicious SQL syntax into database queries. The problem reportedly exists in one of the parameters of the search.php script. This issue is caused by insufficient sanitization of user-supplied data. A remote attacker may exploit this issue to influence SQL query logic to disclose sensitive information that could be used to gain unauthorized access.
Exploit / POC
PHPBB Search.PHP Search_Results Parameter SQL Injection Vulnerability
A proof of concept exploit has been supplied by pokleyzz:
A proof of concept exploit has been supplied by pokleyzz:
Solution / Fix
PHPBB Search.PHP Search_Results Parameter SQL Injection Vulnerability
Solution:
The vendor has released an upgrade that corrects this issue.
phpBB Group phpBB 2.0 .0
phpBB Group phpBB 2.0.1
phpBB Group phpBB 2.0.2
phpBB Group phpBB 2.0.3
phpBB Group phpBB 2.0.4
phpBB Group phpBB 2.0.5
phpBB Group phpBB 2.0.6
Solution:
The vendor has released an upgrade that corrects this issue.
phpBB Group phpBB 2.0 .0
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
phpBB Group phpBB 2.0.1
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
phpBB Group phpBB 2.0.2
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
phpBB Group phpBB 2.0.3
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
phpBB Group phpBB 2.0.4
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
phpBB Group phpBB 2.0.5
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
phpBB Group phpBB 2.0.6
-
phpBB Group phpBB-2.0.8.zip
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.8.zip?download
References
PHPBB Search.PHP Search_Results Parameter SQL Injection Vulnerability
References:
References:
- gemuruh-v2.php.txt (Scan-Associates)
- [SCAN Associates Sdn Bhd Security Advisory] phpBB 2.0.6 and below sql injection (pokley
)