vendor:
Gnuboard5
by:
CodeSecLab
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Gnuboard5
Affected Version From: 5.3.2.8
Affected Version To: 5.3.2.8
Patch Exists: NO
Related CWE: CVE-2020-18662
CPE: gnuboard5:5.3.2.8
Platforms Tested: Ubuntu, Windows
2024
Gnuboard5 5.3.2.8 – SQL Injection
The vulnerability in Gnuboard5 version 5.3.2.8 allows an attacker to execute arbitrary SQL queries through the 'mysql_user', 'mysql_pass', 'mysql_db', and 'table_prefix' parameters in the 'install_db.php' script, leading to unauthorized access to the database. This exploit utilizes SQL injection to manipulate the SQL queries, potentially resulting in data leakage, modification, or deletion. The CVE associated with this vulnerability is CVE-2020-18662.
Mitigation:
To mitigate this issue, sanitize and validate user inputs to prevent SQL injection attacks. Additionally, implement parameterized queries or use ORM frameworks that handle input sanitization.