Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:PHP:PHPBB:PM-SQL-USER

Severity

Low

Recommended

No

Category

HTTP

Keywords

phpbb php

Release Date

2004/06/09

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: phpBB Private Message Parameter SQL Injection


This signature detects attempts to inject SQL code into a request to phpBB, a popular open-source bulletin board application written in php. Attackers can send a maliciously crafted request that supplies SQL commands to the pm_sql_user parameter, changing database values and escalating client privileges.

Extended Description

Reportedly the 'privmsg.php' phpBB script is prone to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI parameters before using them to construct SQL queries to be issued to the underlying database. This may allow a remote attacker to manipulate query logic, potentially leading to access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

Affected Products

  • Francisco Burzi PHP-Nuke 6.0.0
  • Francisco Burzi PHP-Nuke 6.5.0
  • Francisco Burzi PHP-Nuke 6.5.0 BETA 1
  • Francisco Burzi PHP-Nuke 6.5.0 FINAL
  • Francisco Burzi PHP-Nuke 6.5.0 RC1
  • Francisco Burzi PHP-Nuke 6.5.0 RC2
  • Francisco Burzi PHP-Nuke 6.5.0 RC3
  • Francisco Burzi PHP-Nuke 6.6.0
  • Francisco Burzi PHP-Nuke 6.7.0
  • Francisco Burzi PHP-Nuke 6.9.0
  • Francisco Burzi PHP-Nuke 7.0.0
  • Francisco Burzi PHP-Nuke 7.0.0 FINAL
  • Francisco Burzi PHP-Nuke 7.1.0
  • phpBB Group phpBB 2.0.0 .0
  • phpBB Group phpBB 2.0.0 Beta 1
  • phpBB Group phpBB 2.0.0 RC1
  • phpBB Group phpBB 2.0.0 RC2
  • phpBB Group phpBB 2.0.0 RC3
  • phpBB Group phpBB 2.0.0 RC4
  • phpBB Group phpBB 2.0.1
  • phpBB Group phpBB 2.0.2
  • phpBB Group phpBB 2.0.3
  • phpBB Group phpBB 2.0.4
  • phpBB Group phpBB 2.0.5
  • phpBB Group phpBB 2.0.6
  • phpBB Group phpBB 2.0.6 c
  • phpBB Group phpBB 2.0.6 d
  • phpBB Group phpBB 2.0.7
  • phpBB Group phpBB 2.0.7 a
  • phpBB Group phpBB 2.0.8
  • PNphpBB 1.2.0
  • PNphpBB 1.2.0 f
  • PNphpBB 1.2.0 g

References

  • BugTraq: 9984
  • URL: http://www.securityfocus.com/archive/1/358708
  • URL: http://forums.gentoo.org/viewtopic.php?t=63959&sid=fc58045142daeeb15b529452e064aa4b

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out