Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> PunBB profile.php SQL Injection Vulnerability


Vulnerability Assessment Details

PunBB profile.php SQL Injection Vulnerability

Vulnerability Assessment Summary
Checks for SQL injection vulnerability in PunBB's profile.php

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP script that is affected by a SQL
injection flaw.

Description :

According to its banner, the version of PunBB installed on the remote
host fails to properly sanitize user input to the script 'profile.php'
through the 'change_email' parameter prior to using it in a SQL query.
Once authenticated, a possible hacker can exploit this flaw to manipulate
database queries, even gaining administrative access.

See also :

http://marc.theaimsgroup.com/?l=bugtraq&m=111306207306155&w=2

Solution :

Upgrade to PunBB version 1.2.5 or newer.

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)

Networks Security ID: 13071

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors

Toshiba Satellite Radius 11 Intel® Pentium® N3540 CPU @ 2.16GHz. 4GB DDR3. PARTS
$0.01
Toshiba Satellite Radius 11 Intel® Pentium® N3540 CPU @ 2.16GHz. 4GB DDR3. PARTS pictureCPU Cooler Fan bracket heatsink Holder for 2011/1155/1150/1156/1366 Socket~AA
$4.53
CPU Cooler Fan bracket heatsink Holder for 2011/1155/1150/1156/1366 Socket~AA pictureCPU 8pin to 4+4Pin EPS power supply 'cable ATX for corsair RM1000x RM850x R CWUS
$16.12
CPU 8pin to 4+4Pin EPS power supply 'cable ATX for corsair RM1000x RM850x R CWUS pictureDell Inspiron 3668 Motherboard 07KY25 i-Series No CPU Included-Tested
$79.99
Dell Inspiron 3668 Motherboard 07KY25 i-Series No CPU Included-Tested  picture


Discussions

No Discussions have been posted on this vulnerability.