VID |
21758 |
Severity |
40 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Snitz Forums 2000, according to its version number, has an SQL injection vulnerability in the register.asp script. Snitz Forums 2000 is ASP-based web forum software, developed by Snitz Communications. Snitz Forums 2000 version 3.3.03 and earlier versions could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the Email variable of the register.asp script. This vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself. A remote attacker could exploit this flaw to obtain sensitive information, including the password hashes of users and the super administrator. A successful attack would also allow the remote attacker the ability to potentially execute arbitrary system commands through common SQL stored procedures such as xp_cmdshell.
* Note: This check solely relied on the version number of Snitz Forums program installed on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html
* Platforms Affected: Snitz Communications, Snitz Forums 2000 version 3.3.03 and earlier versions Any operating system Any version |
Recommendation |
Upgrade to the latest version of Snitz Forums 2000 (3.4.03 or later), available from the Snitz Forums 2000 Web site at http://forum.snitz.com |
Related URL |
CVE-2003-0286 (CVE) |
Related URL |
7549 (SecurityFocus) |
Related URL |
11981 (ISS) |
|