CERTA-2002-AVI-106
Vulnerability from certfr_avis
Une vulnérabilité présente dans Snitz Forums 2000 donne accès à la base de données du forum.
Description
Snitz Forums 2000 est un forum populaire qui fonctionne sous Windows.
Un utilisateur mal intentionné peut, en manipulant des requêtes SQL, accéder à la base de données du forum, en particulier aux identifiants des utilisateurs et à leur mot de passe. Cette vulnérabilité est exploitable à distance.
Solution
Télécharger la version 3.3.04 de Snitz Forums 2000 au lien suivant :
http://forum.snitz.com/download.asp
Snitz Forums 2000 versions 3.3, 3.3.01, 3.3.02 et 3.3.03.
Impacted products
| Vendor | Product | Description |
|---|
References
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cP\u003e\u003cTT\u003eSnitz Forums 2000\u003c/TT\u003e versions 3.3, 3.3.01, 3.3.02 et 3.3.03.\u003c/P\u003e",
"content": "## Description\n\nSnitz Forums 2000 est un forum populaire qui fonctionne sous Windows.\n\nUn utilisateur mal intentionn\u00e9 peut, en manipulant des requ\u00eates SQL,\nacc\u00e9der \u00e0 la base de donn\u00e9es du forum, en particulier aux identifiants\ndes utilisateurs et \u00e0 leur mot de passe. Cette vuln\u00e9rabilit\u00e9 est\nexploitable \u00e0 distance.\n\n## Solution\n\nT\u00e9l\u00e9charger la version 3.3.04 de Snitz Forums 2000 au lien suivant :\n\n http://forum.snitz.com/download.asp\n",
"cves": [],
"initial_release_date": "2002-05-17T00:00:00",
"last_revision_date": "2002-05-17T00:00:00",
"links": [
{
"title": "Annonce de Snitz Forums 2000:",
"url": "http://forum.snitz.com/forum/topic.asp?TOPIC_ID=28195"
}
],
"reference": "CERTA-2002-AVI-106",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2002-05-17T00:00:00.000000"
}
],
"risks": [
{
"description": "Compromission de la base de donn\u00e9es du forum"
}
],
"summary": "Une vuln\u00e9rabilit\u00e9 pr\u00e9sente dans Snitz Forums 2000 donne acc\u00e8s \u00e0 la base\nde donn\u00e9es du forum.\n",
"title": "Vuln\u00e9rabilit\u00e9 dans Snitz Forums 2000",
"vendor_advisories": []
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…