Philboard.Philboardforum.Asp.SQL.Injection

description-logoDescription

Philboard has a SQL-injection vulnerability. A remote attacker could execute arbitrary SQL commands in the back-end database via a specially-crafted HTTP request to the "philboard_forum.asp" script with injected SQL statements in the "forumid" parameter.

affected-products-logoAffected Products

Philboard version 1.14 and prior.

Impact logoImpact

Data Manipulation.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.
http://www.nabocorp.com/nabopoll/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)