Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

phpBB Profile.PHP SQL Injection Vulnerability

A SQL injection vulnerability has been reported for phpBB systems.

phpBB, in some cases, does not sufficiently sanitize user-supplied input, which is used when constructing SQL queries to execute on the underlying database. As a result, it is possible to manipulate SQL queries. This may allow a remote attacker to modify query logic or potentially corrupt the database.

SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.







 

Privacy Statement
Copyright 2009, SecurityFocus