From: Support Service To: moderators@osvdb.org Date: Tue, 22 Nov 2005 19:45:32 -0500 Subject: [OSVDB Mods] WSN Forum "id" SQL Injection Vulnerability WSN Forum "id" SQL Injection Vulnerability Vuln. dicovered by : r0t Orginal advisory:http://pridels.blogspot.com/2005/11/wsn-forum-id-sql-injection.html Vendor:http://www.wsnforum.com/ affected version:1.21 and maybe prior versions. Vuln Description: Input passed to the "id" parameter in "memberlist.php" isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Example: /[forum_path]/memberlist.php?action=profile&id=1[SQL] Solution: Edit the source code to ensure that input is properly sanitised.