|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Invision Power Board CLIENT_IP SQL Injection Vulnerability Vulnerability Assessment Details
|
Invision Power Board CLIENT_IP SQL Injection Vulnerability |
||
Checks version of IPB Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a PHP application that is susceptible to a SQL injection attack. Description : According to its banner, the installation of Invision Power Board on the remote host reportedly fails to sanitize input to the 'CLIENT_IP' HTTP request header before using it in database queries. An unauthenticated attacker may be able to leverage this issue to disclose sensitive information, modify data, or launch attacks against the underlying database. Note that it's unclear whether successful exploitation depends on any PHP settings, such as 'magic_quotes'. See also : http://www.milw0rm.com/exploits/2010 http://www.nessus.org/u?eea8694e Solution : Upgrade to Invision Power Board 2.1.7 or later. Network Security Threat Level: High / CVSS Base Score : 7 (AV:R/AC:L/Au:NR/C:P/A:P/I:P/B:N) Networks Security ID: 18984 Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security |
||
Cables, Connectors |
Mini External OLED AMIGA Gotek Floppy Drive Emulator For Amiga 500/500+/600/1200
$39.20
Commodore Amiga A2386SX Bridge board
$900.00
Brand New Amiga 4000T Keyboard
$299.99
Commodore Amiga Stereo Sound Sampler Techno Sound Turbo Technosound HW & SW pack
$50.99
Commodore Amiga 3000 030 25Mhz + Keyboard + Mouse - Amiga OS 3.2 - WORKS 100%
$1599.99
Amiga 500 Gotek Custom Mount USB Floppy Emulator - Complete Kit with Gotek
$65.00
Commodore 64 Disk Drive, Includes Cables & Manuals.
$60.00
Amiga MiniMig 2.0 - FPGA Amiga 500 with real 68000CPU
$179.99
AMIGA 500 COMPUTER COMMODORE Complete in Box Powers/untested Good Condition
$370.00
Raemixx500 Commodore Amiga500+ V2 Remake PCB Gold Plated
$35.15
|
||
No Discussions have been posted on this vulnerability. |