Sunday, November 20, 2011

6rbScript 'section.php' Local File Include Vulnerability

This vulnerability report for 6rbScript 3.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

6rbScript is a web application implemented in PHP.

The application is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data to the 'CatID' parameter of the 'cat.php' script before using it in an SQL query.

A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.