|
Family: CGI abuses --> Category: attack
Burning Board verify_email SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for verify_email SQL injection vulnerability in Burning Board
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is prone to SQL
injection attacks.
Description :
The version of Burning Board or Burning Board Lite installed on the
remote host suffers from a SQL injection vulnerability in the way it
verifies email addresses when, for example, a user registers. An
attacker can exploit this flaw to affect database queries, including
possible disclosure of sensitive information.
See also :
http://www.gulftech.org/?node=research&article_id=00075-05162005
Solution :
Contact the vendor for a patch.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|