|
Family: CGI abuses --> Category: infos
Hosting Controller ForumID Parameter SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for a SQL injection flaw in Hosting Controller
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains an ASP application that is susceptible
to a SQL injection attack.
Description :
The installed version of Hosting Controller fails to sanitize input to
the 'ForumID' parameter of the 'forum/HCSpecific/EnableForum.asp'
script before using it in database queries. An unauthenticated
attacker may be able to leverage this issue to manipulate database
queries to reveal sensitive information, modify data, launch attacks
against the underlying database, etc.
See also :
http://www.kapda.ir/advisory-442.html
Solution :
Unknown at this time.
Threat Level:
High / CVSS Base Score : 7
(AV:R/AC:L/Au:NR/C:P/A:P/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|