|
Family: CGI abuses --> Category: attack
Limbo catid Parameter SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Tries to affect DB queries in Limbo CMS
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is affected by a SQL
injection issue.
Description :
The remote host is running Limbo CMS, a content-management system
written in PHP.
The version of Limbo CMS installed on the remote host fails to
sanitize input to the 'catid' parameter of the 'index.php' script
before using it in a database query. An unauthenticated attacker may
be able to leverage this issue to manipulate SQL queries to uncover
password hashes for arbitrary users of the affected application.
Note that successful exploitation requires that Limbo is configured to
use MySQL for its database backend, which is not the default.
See also :
http://www.securityfocus.com/archive/1/433221/30/0/threaded
http://forum.limboforge.org/index.php?topic=6.0
http://limboforge.org/web/component/option,com_remository/Itemid,1/func,fileinfo/id,115/
Solution :
Apply Cumulative Patch v8 to Limbo 1.0.4.2 as referenced in the
advisories above.
Threat Level:
Medium / CVSS Base Score : 4
(AV:R/AC:H/Au:NR/C:P/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|