[VulnDiscuss] Re: phpBB password disclosure by sql injection

Evert Jan van Ramselaar <[email protected]> Fri, 20 Jun 2003 22:43:14 +0200
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Organization Van Ramselaar Info Tech
Message-ID <[email protected]>
Rick wrote:
> There is sql injection vuln in phpBB. The variable "topic_id" is passed
> directly from GET to sql query in /viewtopic.php. It can be used 
> to get md5 passwords for users. I am attaching details and proof of
> concept code.  I've only tested this on mysql 4 and pgsql at my home
> machines so I might have missed something...

The phpBB Group has confirmed this and a fix is available:
http://www.phpbb.com/phpBB/viewtopic.php?t=112052

-- 
   Evert Jan van Ramselaar  <[email protected]>
   Van Ramselaar Info Tech  <http://www.vanramselaar.nl>