| VID |
21745 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The PunBB software, according to its version number, has an SQL injection vulnerability in the search.php script. PunBB is a freely available, open source PHP-based bulletin board software. PunBB versions prior to 1.2.9 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'old_searches' parameter of the 'search.php' script. If the register_globals option is enabled, this vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.
* Note: This check solely relied on the version number of PunBB installed on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://www.securityfocus.com/archive/1/413481
* Platforms Affected: Rickard Andersson, PunBB versions prior to 1.2.9 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of PunBB (1.2.9 or later), available from the PunBB Download Web site at http://www.punbb.org/downloads.php |
| Related URL |
CVE-2005-3518 (CVE) |
| Related URL |
15114 (SecurityFocus) |
| Related URL |
22760 (ISS) |
|