| Name | 427BB.Showthread.PHP.ForumID.Parameter.SQL.Injection |
| Release Date | Nov 11, 2009 |
| Severity | Medium |
| Impact | Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems. |
| Description | This indicates an attack attempt to exploit an SQL-injection vulnerability in 427BB.
The vulnerability is a result of the application's failure to properly sanitize user input before using it in an SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server. |
| Affected Products | 427BB 2.2 427BB 2.2.1 |
| Recommended Actions | Upgrade the software to the latest versions. |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-0154
|
| Reference/s | http://www.securityfocus.com/bid/16169 (BugTraq)
|