|
Family: CGI abuses --> Category: attack
phpBB Knowledge Base Module SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for SQL injection vulnerability in phpBB Knowledge Base module
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application affected by a cross-
site scripting issue.
Description :
The installed version of phpBB on the remote host includes the
Knowledge Base module, which does not properly sanitize input to the
'cat' parameter of the 'kb.php' script before using it in SQL queries.
A possible hacker can exploit this flaw to modify database queries,
potentially even uncovering user passwords for the application.
See also :
http://www.securityfocus.com/archive/1/396098
Solution :
Unknown at this time.
Threat Level:
Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|