|
|
|
|
|
|
|
| |
Invision Community Blog Module eid Parameter SQL Injection |
|
| This script is Copyright (C) 2005-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 16154 (invision_community_board_sql_injection.nasl) |
| Bugtraq ID | 12205
|
| CVE ID | CVE-2005-0217
|
|
| Description: |
Synopsis :
The remote web server is a hosting an application that is affected
by a SQL injection vulnerability.
Description :
The remote host appears to be running Invision Community Blog, a
weblog utility.
There is a flaw in the remote software which may allow anyone to
inject arbitrary SQL commands through the 'index.php' script, which
may in turn be used to gain administrative access on the remote host.
See also :
http://archives.neohapsis.com/archives/bugtraq/2005-01/0078.html
http://www.nessus.org/u?2679d827
Solution :
Patches are available from the above reference.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|