Korean
<< Back
VID 21513
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The UBB.threads, according to its version number, has an SQL injection vulnerability in the editpost.php script. UBB.Threads is a bulletin board system written in PHP. UBBThreads versions 3.4.x and 3.5 allow a remote attacker to execute arbitrary SQL commands, due to the application failing to properly sanitize user-supplied input to the Number parameter before using it in SQL queries in the editpost.php script. This vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.

* Note: This check solely relied on the version number of the UBB.threads installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://secunia.com/advisories/14578/

* Platforms Affected:
InfoPop Corporation, UBBThreads 6.5.1.1 and earlier
Microsoft Windows Any version
Linux Any version
Unix Any version
Recommendation Upgrade to the latest version of UBB.Threads (6.5.1.1 or later), available from the UBB.Threads Web site at http://www.ubbcentral.com/
Related URL CVE-2005-0726 (CVE)
Related URL 12784 (SecurityFocus)
Related URL 19673 (ISS)