|
Family: CGI abuses --> Category: attack
Invision Power Board st Parameter SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for st parameter SQL injection vulnerability in Invision Power Board
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is affected by a SQL
injection vulnerability.
Description :
A version of Invision Power Board installed on the remote host suffers
from a SQL injection vulnerability due to its failure to sanitize user
input via the 'st' parameter to the 'index.php' script. A possible hacker can
take advantage of this flaw to inject arbitrary SQL statements into
Invision Power Board, possibly even modifying the database.
See also :
http://www.securityfocus.com/archive/1/395515
Solution :
Unknown at this time.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|