Family: CGI abuses --> Category: attack
Burning Board boardids Parameter SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Tries to generate a SQL error
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that is prone to a SQL
The version of Burning Board / Burning Board Lite on the remote host
fails to sanitize user input to the 'boardids' parameter of the
'search.php' script before using it in database queries. Regardless
of PHP's 'register_globals' and 'magic_quotes_gpc' settings, an
unauthenticated remote attacker can leverage this issue to launch SQL
injection attacks against the affected application, including
discovery of password hashes of users of the application.
See also :
Unknown at this time.
High / CVSS Base Score : 7
Click HERE for more information and discussions on this network vulnerability scan.