Short Name |
HTTP:PHP:PHPBB:PM-SQL-USER |
---|---|
Severity |
Warning |
Recommended |
No |
Category |
HTTP |
Keywords |
phpBB Private Message Parameter SQL Injection |
Release Date |
2004/06/09 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to inject SQL code into a request to phpBB, a popular open-source bulletin board application written in php. Attackers can send a maliciously crafted request that supplies SQL commands to the pm_sql_user parameter, changing database values and escalating client privileges.
Reportedly the 'privmsg.php' phpBB script is prone to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI parameters before using them to construct SQL queries to be issued to the underlying database. This may allow a remote attacker to manipulate query logic, potentially leading to access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.