PT-2006-5770 · Php+2 · Php+2
Published
2006-09-27
·
Updated
2018-10-17
·
CVE-2006-5029
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WoltLab Burning Board (wBB) versions 2.3.x
Description
A SQL injection issue in the thread.php file of WoltLab Burning Board (wBB) allows remote attackers to obtain version numbers of PHP, MySQL, and wBB by manipulating the
page parameter. This issue might be related to a forced SQL error.Recommendations
For WoltLab Burning Board (wBB) versions 2.3.x, update to a version where this issue is resolved, if available. As a temporary workaround, consider restricting access to the thread.php file to minimize the risk of exploitation. Avoid using the
page parameter in the affected thread.php file until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql Server
Php
Woltlab Burning Board