Document Title: =============== Forumer & IPB Board - Remote SQL Injection Vulnerability Release Date: ============= 2011-06-20 Vulnerability Laboratory ID (VL-ID): ==================================== 199 Abstract Advisory Information: ============================== linc0ln.dll detected a SQL Injection Vulnerability on the Forumer Board Application of IPB. Vulnerability Disclosure Timeline: ================================== 2011-06-11: Detected by Researcher 2011-06-18: Vendor Notification 2011-06-19: Vendor Response/Feedback 2011-00-00: Vendor Fix/Patch 2011-06-20: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== High Technical Details & Description: ================================ A remote SQL Injection vulnerability is detected for the new Forumer & IPB Web Application. The vulnerability allows an attacker (remote) to inject own sql statements over a not secure parsed parameter. Vulnerable Module(s): [+] Show Topic (param) --- SQL Error Logs --- mySQL query error: SELECT title from soundt_topics where tid=-1.- mySQL error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near at line 1 ... or mySQL query error: SELECT title from watblog_topics where tid={SQL} mySQL error: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near }- at line 1 Pictures: ../1.png Proof of Concept (PoC): ======================= The vulnerability can be exploited by remote attackers (pre-auth). For demonstration or reproduce ... PoC: http://127.0.0.1/[path]/index.php?showtopic={SQL} References: http://www.sound-thinking.org/index.php?showtopic={SQL} http://kiss2wat.co.nr/index.php?showtopic={SQL} http://www.javelin70.com/index.php?showtopic={SQL} Dork: "Powered by Forumer & IPB" ... or