GNUTurk.TID.Parameter.Forum.SQL.Injection

description-logoDescription

This indicates an attempt to exploit a SQL injection vulnerability in GNUTURK.
A remote attacker could execute arbitrary SQL commands in the back-end database via a specially-crafted HTTP request to the "mods.php" script with injecting SQL statements in "t_id" parameter.

affected-products-logoAffected Products

GNUTURK PORTAL 2G and prior.

Impact logoImpact

Data Manipulation.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)