Press CTRL-D to bookmark us
Welcome Guest Login / Register / Members
Search in  
Top Submit newsSubscribe
Communication | Computer Crime | Digital Audio, Video, Photo | General News | Hardware | Internet | Mobile | PDA | Security | Software | Vulnerability |


Previous articleBack to news listNext article
 

 Sponsored links

Want to become one of our authors and see your work published on ALLSeek.iNFO ?
 
 phpBB Input Validation Flaw in 'search_id' Permits SQL Injection and Yields Administrative Access
Categorie: Vulnerability
Posted: 2003-12-01 by ReCall
Views: 397
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Description: An input validation vulnerability was reported in phpBB in 'search.php'. A remote user can inject SQL commands to gain administrative access to the forum.

It is reported that the 'search.php' script does not properly validate the 'search_id' parameter. A remote user can send a specially crafted value to execute certain SQL commands on the target server, such as a command to obtain the administrator's hashed password. With the hashed password, a remote user can then modify their cookies to gain access to the system.

To determine if your system has been patched, run the following query:

http://your_site/phpBB2/search.php?search_id=1

If your system is patched, the system will display the following message:

"No topics or posts met your search criteria"

Impact: A remote user can inject SQL commands to gain administrative access to the forum.

Solution: The vendor has fixed the latest version of 2.06, available at:



http://www.phpbb.com/

A description of how to manually fix the flaw is available at:

http://www.phpbb.com/phpBB/viewtopic.php?t=153818
 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://allseek.info/news/trackback.php?id=572

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 



InterJOB.su

SpyLOG Page Rank Checker
LAST QUERIES