This application requires Javascript for optimal performance.

Venom.Board.Post.PHP3.Topic.ID.SQL.Injection

Release Date

Nov 19, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit an SQL-injection vulnerability in Venom Board.

The vulnerability is a result of the application's failure to properly sanitize user input before using it in an SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server.

Affected Products

Venom Board 1.22

Recommended Actions

Currently we are not aware of any officially supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-0160

Reference/s

http://www.securityfocus.com/bid/16176 (BugTraq)

Reference: VID-17904