This application requires Javascript for optimal performance.

Snitz.Forums.Pop_Profile.SQL.Injection

Release Date

Apr 13, 2007

Severity

medium

Impact

SQL injection.

Description

Snitz Forums 2000 has an SQL injection vulnerability. A remote attacker could execute arbitrary SQL commands in the back-end database via a specially-crafted HTTP request to the "pop_profile.asp" script with the "id" parameter.

Affected Products

Snitz Forums 2000 3.1 SR4

Recommended Actions

Currently we are not aware of any official supplied fix for this issue.
http://forum.snitz.com/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-1023

Reference/s

http://www.securityfocus.com/bid/22593 (BugTraq)

Reference: VID-14474