Korean
<< Back
VID 21245
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The phpBB installed on the Web server has a SQL injection vulnerability.
The phpBB is a open-source bulletin board software package, which uses MySQL, MS-SQL, PostgreSQL or Access/ODBC database. This SQL injection vulnerability arises due to handling insufficiently user-supplied input passed to the "viewtopic.php" script. By sending the topic_id variable containing SQL queries to the "viewtopic.php" script, a remote attacker can manipulate the underlying database. Using this vulnerability, a remote attacker can gain the MD5 password hash for users, modify query logic or corrupt the database.

* References:
http://archives.neohapsis.com/archives/bugtraq/2003-06/0151.html

* Platforms Affected:
phpBB 2.0.4
phpBB 2.0.5
Linux Any version
Unix Any version
Windows Any version
Recommendation No vendor-supplied patch for this vulnerability as of June, 2003.

As a workaround, you can obtain a temporary fix from phpBB forums at http://www.phpbb.com/phpBB/viewtopic.php?t=112052 .
Related URL CVE-2003-0486 (CVE)
Related URL 7979 (SecurityFocus)
Related URL 12366 (ISS)