|
Family: CGI abuses --> Category: infos
UBB.threads editpost.php SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for SQL injection vulnerability in UBB.threads editpost.php
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is prone to
SQL injection attacks.
Description :
According to its banner, the remote host is running a version of
UBB.threads that fails to sufficiently sanitize the 'Number' parameter
before using it in SQL queries in the 'editpost.php' script. As a
result, a remote attacker can pass malicious input to database queries,
potentially resulting in data exposure, modification of the query logic,
or even data modification or attacks against the database itself.
See also :
http://marc.theaimsgroup.com/?l=bugtraq&m=111056135818279&w=2
Solution :
Upgrade to UBB.threads version 6.5.1.1 or greater.
Threat Level:
Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:C)
Click HERE for more information and discussions on this network vulnerability scan.
|