HTTP: phpBB Private Message Parameter SQL Injection

This signature detects attempts to inject SQL code into a request to phpBB, a popular open-source bulletin board application written in php. Attackers can send a maliciously crafted request that supplies SQL commands to the pm_sql_user parameter, changing database values and escalating client privileges.

Extended Description

Reportedly the 'privmsg.php' phpBB script is prone to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI parameters before using them to construct SQL queries to be issued to the underlying database. This may allow a remote attacker to manipulate query logic, potentially leading to access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

Affected Products

Francisco_burzi php-nuke

Short Name
HTTP:PHP:PHPBB:PM-SQL-USER
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Injection Message Parameter Private SQL bid:9984 phpBB
Release Date
06/09/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Francisco_burzi

Pnphpbb

Phpbb_group

Found a potential security threat?