QUOTE
FrSIRT Advisory : FrSIRT/ADV-2005-1368
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-08-10

* Technical Description *

Two vulnerabilities were identified in XMB Forum, which could be exploited by malicious users to conduct SQL injection attacks or overwrite server set variables.

This first issue is due to an input validation error in the "xmb.php" script when extracting variables, which may be exploited by attackers to overwrite server set variables via a specially crafted form (i.e. "_SERVER[REMOTE_ADDR]").

The second flaw is due to an input validation error in the "include/u2u.inc.php" script when processing a specially crafted "in" variable via the "u2u_select" parameter, which may be exploited by remote users to conduct SQL injection attacks.

* Affected Products *

XMB Forum version 1.9.1 and prior

* Solution *

The FrSIRT is not aware of any official supplied patch for this issue.

* References *

http://www.frsirt.com/english/advisories/2005/1368
http://forums.xmbforum.com/viewthread.php?tid=754523

* Credits *

Vulnerabilities reported by Heintz

* ChangeLog *

2005-08-10 : Original Advisory


I hope someone use this to make exploit... ph34r.gif