| VID |
21612 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The IkonBoard program is vulnerable to an SQL injection vulnerability in the ikonboard.cgi file. IkonBoard is a freely available Web Bulletin Board System written in Perl. IkonBoard versions 3.1.0 through 3.1.3 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'st' and 'keywords' parameters of the 'ikonboard.cgi' file. This vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.
* References: http://archives.neohapsis.com/archives/bugtraq/2004-12/0192.html
* Platforms Affected: Jarvis Entertainment Group, Inc., IkonBoard versions 3.1.0 through 3.1.3 Any operating system Any version |
| Recommendation |
No upgrade or patch available as of June 2005.
Upgrade to the latest version of IkonBoard, when new version fixed this problem becomes available from the IkonBoard Web site at http://www.ikonboard.com/ |
| Related URL |
CVE-2004-1406 (CVE) |
| Related URL |
11982 (SecurityFocus) |
| Related URL |
18533 (ISS) |
|