Short Name |
HTTP:PHP:PHPBB:SELECT-FISH |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
phpBB User Select Fish Attack |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in phpBB. PhpBB versions 2.0, 2.01, and 2.02 are vulnerable. Attackers can use SQL injection attacks to obtain phpBB user passwords and to gain administrative access to the phpBB interface.
A SQL injection vulnerability has been reported in phpBB2. phpBB2, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries. This may result in unauthorized operations being performed on the underlying database. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.