Title : phpBP "id" Parameter Processing Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2008-0910 CVE ID : CVE-2008-1408
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-18
Technical Description
A vulnerability has been identified in phpBP, which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by an input validation error in the "banner_out()" [includes/functions/banners-external.php] function when processing the "id" parameter, which could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information.