Synopsis
The remote web server is hosting a CGI application that is affected by multiple SQL injection vulnerabilities.
Description
The remote server is running NetPleasure's Instaboard.
There is a bug in this release which allow an attacker to perform a SQL injection attack through the page 'index.cfm'.
An attacker may use this flaw to gain unauthorized access to take the control of the remote database.
Solution
There is no known solution at this time.
Plugin Details
File Name: instaboard_sql_injection.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7338