Synopsis
The remote host has an application that is affected by a SQL injection vulnerability.
Description
The remote host is running MegaBBS, a web-based bulletin board system written in ASP.
The remote version of this software is vulnerable to a SQL injection attack due to a lack of sanitization of user-supplied input. An attacker may exploit this flaw to issue arbitrary statements in the remote database, and therefore, bypass authorization or even overwrite arbitrary files on the remote system.
Solution
Upgrade to version 2.1 or later.
Plugin Details
File Name: pd9_megabbs_flaws.nasl
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:pd9_software:megabbs
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 11253