SQL injection in BttlxeForum

From: SecurityTracker (help@securitytracker.com)
Date: 04/24/03

  • Next message: NSFOCUS Security Team: "NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS"
    Date: Wed, 23 Apr 2003 22:05:30 -0400
    From: SecurityTracker <help@securitytracker.com>
    To: bugtraq@securityfocus.com
    
    

    Hi,

    SAUDI_DEFACERZ reported an input validation vulnerability in the 'bttlxeForum' forum
    software earlier today. A remote user can gain full control over the application.

    You can see the original message from SAUDI_DEFACERZ at:

    http://securitytracker.com/alerts/2003/Apr/1006632.html

    The vendor responded rapidly to provide a fix:

    23 April 2003, 14:43 UTC/GMT - Vendor notified
    23 April 2003, 14:56 UTC/GMT - Vendor responded
    23 April 2003, 16:03 UTC/GMT - Vendor posted fix
    23 April 2003, 16:11 UTC/GMT - Vendor responded to indicate that a fix was available.

    See the vendor's bug fix announcement at:

    http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&select=1812

    CVE Number is CAN-2003-0215.

    Stuart


  • Next message: NSFOCUS Security Team: "NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS"

    Relevant Pages