Korean
<< Back
VID 21612
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The IkonBoard program is vulnerable to an SQL injection vulnerability in the ikonboard.cgi file. IkonBoard is a freely available Web Bulletin Board System written in Perl. IkonBoard versions 3.1.0 through 3.1.3 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'st' and 'keywords' parameters of the 'ikonboard.cgi' file. This vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.

* References:
http://archives.neohapsis.com/archives/bugtraq/2004-12/0192.html

* Platforms Affected:
Jarvis Entertainment Group, Inc., IkonBoard versions 3.1.0 through 3.1.3
Any operating system Any version
Recommendation No upgrade or patch available as of June 2005.

Upgrade to the latest version of IkonBoard, when new version fixed this problem becomes available from the IkonBoard Web site at http://www.ikonboard.com/
Related URL CVE-2004-1406 (CVE)
Related URL 11982 (SecurityFocus)
Related URL 18533 (ISS)