Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  File Including In PBLang

  [SA17333] phpESP Unspecified Cross-Site Scripting and SQL Injection

  [SA17353] gCards "limit" SQL Injection Vulnerability

  [Full-disclosure] Multiple vulnerabilities within RockLiffe MailSite Express WebMail

From:admin_(at)_batznet.com <admin_(at)_batznet.com>
Date:27.10.2005
Subject:Woltlab Burning Board info_db.php multiple SQL injection

#################################################################
#
#   Woltlab Burning Board info_db.php multiple SQL      #   injection    
#                                               
#################################################################
->discovered by [R]


Vendor: "Trooper"
URL:  www.wbbcoderforum.de
Version: <= 2.7
Type: SQL-injection


Description:
------------------------
Info-DB is a very powerful and popular download-module with many features.


Information:
------------------------
Info-DB is prone to multiple SQL injection vulnerabilities.
(It's possible to upload any files through info_db.php.)


Bug:
------------------------
[1] /info_db.php?action=file&fileid=[SQL-Injection]
[2] /info_db.php?action=file&fileid=59&subkatid=[SQL-injection]

Both tested on 2.5.
All other versions should be vulnerable, too.
An exploit-code is available at rootbox.cx.la/batznet.com


Patch:
------------------------
No Patch available.


Greetz:
------------------------
greetz fly out to 2lm, Lux2, redice, triple6, darkkilla, EaTh




// written by [R]
// www.batznet.com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru