Psi Social Networking Script myprofile.php SQL injection
| psisocial-myprofile-sql-injection (36557) |
Description:
Psi Social Networking Script is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the profile/myprofile.php script using the u parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.
Platforms Affected:
- psi-labs.com, Psi Social Networking Script 1.0 and prior
Remedy:
No remedy available as of July 4, 2009.
Consequences:
Data Manipulation
References:
- BugTraq Mailing List, Sat Sep 08 2007 - 23:45:02 CDT, [Aria-Security Team] social-networkin SQL Injection at http://archives.neohapsis.com/archives/bugtraq/2007-09/0097.html.
- psi-labs Web site, Psi Social Networking Script at http://www.psi-labs.com/socialnetworking_script.html.
- BID-25631: psi-labs.com psisns SQL Injection Vulnerability
- CVE-2007-4881: SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter.
- SA26774: Psi Social Networking Script "u" SQL Injection Vulnerability
- VUPEN/ADV-2007-3128: PSI Social Networking Script u Parameter Remote SQL Injection Vulnerability
Reported:
Sep 11, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
