J-Security Center

Title: YABB SE SSI.PHP ID_MEMBER SQL Injection Vulnerability

Severity: HIGH

Description:

YaBB SE is a freely available, open source port of Yet Another Bulletin Board (YaBB). It is available for Unix, Linux, and Microsoft Operating Systems.

A problem with YaBB SE could make it possible for a remote user to launch SQL injection attacks.

It has been reported that a problem exists in the SSI.php script distributed as part of YaBB SE. Due to insufficient sanitizing of the user-supplied ID_MEMBER URI parameter, it is possible for a remote user to inject arbitrary SQL queries into the database used by YaBB SE. This could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

Successful exploitation could result in compromise of the YaBB SE, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Affected Products:

  • YaBB SE YaBB SE 0.8.0
  • YaBB SE YaBB SE 1.1.3
  • YaBB SE YaBB SE 1.4.1
  • YaBB SE YaBB SE 1.5.0.0
  • YaBB SE YaBB SE 1.5.0.1 RC1
  • YaBB SE YaBB SE 1.5.1
  • YaBB SE YaBB SE 1.5.2
  • YaBB SE YaBB SE 1.5.3
  • YaBB SE YaBB SE 1.5.4

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.