OSVDB ID: 17506

Title: Forum Russian Board (FRB) in.php Multiple Variable SQL Injection

Info

Disclosure

Jun 21, 2005

Discovery

Apr 24, 2005

Dates

Exploit

Jun 21, 2005

Solution

Unknown

Description

Forum Russian Board (FRB) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'in.php' script not properly sanitizing user-supplied input to the 'name_new' and 'email_new' variables. This may allow a remote attacker to inject or manipulate SQL queries in the backend database.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Available
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Gavrilov Dmitriy

Forum Russian Board (FRB)

4.2

References

Credit

  • 1dt.w0lf & foster - Personal Page


Direct URL: http://osvdb.org/36218