This application requires Javascript for optimal performance.

WordCircle.Input.Validation.SQL.Injection

Release Date

Nov 09, 2011

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit one of several vulnerabilities in TheWebForum.

The vulnerability is a result of the application's failure to properly sanitize user supplied input. As a result, remote attackers can execute arbitrary script code within the context of the application or escalate their privileges.

Affected Products

Wordcircle Wordcircle 2.17 and earlier versions.

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-0205

Reference/s

http://www.securityfocus.com/bid/16227 (BugTraq)

Reference: VID-29819