|
Family: CGI abuses --> Category: attack
Invision Power Board Dragoran Portal Plugin site Parameter SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for site parameter SQL injection vulnerability in Invision Power Board Dragoran Portal Plugin
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application that is affected by
SQL injection attacks.
Description :
The installation of Invision Power Board on the remote host contains
an optional test module known as Dragoran Portal that fails to
sanitize input to the 'site' parameter of the 'index.php' script
before using it in database queries. A possible hacker may be able to
leverage this issue to disclose sensitive information, modify data, or
launch attacks against the underlying database.
Solution :
Unknown at this time.
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|