File: 2229.txt

package info (click to toggle)
snort 2.7.0-20.4
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 34,512 kB
  • ctags: 18,772
  • sloc: ansic: 115,404; sh: 10,893; makefile: 1,372; perl: 487; sql: 213
file content (57 lines) | stat: -rw-r--r-- 1,065 bytes parent folder | download | duplicates (6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
Rule:  

--
Sid:
2229

--
Summary:
This event is generated when an attempt is made to exploit a known 
vulnerability in the PHP application phpBB.

--
Impact:
Information disclosure possibly leading to serious system compromise.

--
Detailed Information:
Some versions of phpBB Group phpBB suffer from a vulnerability that 
allows an attacker to inject SQL queries of their choosing.

This can result in the disclosure of passwords and other information 
stored in the database. The data contained in the database may also be 
corrupted by a malicious SQL query.

--
Affected Systems:
	phpBB Group phpBB 2.0.4, 2.0.5

--
Attack Scenarios:
The attacker can execute one of the publicly available exploit scripts.
--
Ease of Attack:
Simple. Exploit code exists.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Upgrade to the latest non-affected version of the software.

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

-- 
Additional References:

--