Vulnerabilities > CVE-2007-1902 - SQL Injection vulnerability in Sonicbb 1.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php, or the (2) id parameter to (b) viewforum.php. Successful exploitation requires that "magic_quotes_gpc" is disabled.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | SonicBB 1.0 Multiple SQL Injection Vulnerabilities. CVE-2007-1902. Webapps exploit for php platform |
id | EDB-ID:30035 |
last seen | 2016-02-03 |
modified | 2007-05-14 |
published | 2007-05-14 |
reporter | Jesper Jurcenoks |
source | https://www.exploit-db.com/download/30035/ |
title | SonicBB 1.0 - Multiple SQL Injection Vulnerabilities |
Packetstorm
data source | https://packetstormsecurity.com/files/download/56722/sbb-sql.txt |
id | PACKETSTORM:56722 |
last seen | 2016-12-05 |
published | 2007-05-15 |
reporter | Jesper Jurcenoks |
source | https://packetstormsecurity.com/files/56722/sbb-sql.txt.html |
title | sbb-sql.txt |
References
- http://marc.info/?l=full-disclosure&m=117914598917534&w=2
- http://secunia.com/advisories/25279
- http://www.netvigilance.com/advisory0019
- http://www.osvdb.org/33907
- http://www.securityfocus.com/archive/1/468536/100/0/threaded
- http://www.securityfocus.com/bid/23964
- http://www.vupen.com/english/advisories/2007/1816
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34258