HTTP: phpBB UserID Parameter SQL Injection
This signature detects maliciously crafted requests to phpBB; phpBB versions 2.0.6 and earlier are vulnerable. Attackers can inject SQL commands into the "u" parameter in a request to profile.php and gain direct access to the database used by phpBB.
Extended Description
phpBB fails to properly handle user requests. By sending a specially crafted URL request, the attacker could execute arbitrary SQL commands on the server.
References
URL: http://www.security.nnov.ru/search/document.asp?docid=5365
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3