Release date:
Updated on:
Affected Systems:
Tforum
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-5137
Tforum is a free Twitter forum.
Tforum has the SQL injection vulnerability. Remote attackers can send specially crafted data to viewtopics that use the TopicID, BoardID, and CatID parameters. php, viewboard. php, viewcat. php script, resulting in viewing, adding, and deleting information in the backend database.
<* Source: vendor
Link: http://xforce.iss.net/xforce/xfdb/71975
Http://packetstormsecurity.org/files/view/108184/tforum-sqlxss.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Tforum
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://tforum.com/