Synopsis
The remote web server has an application that is affected by a SQL injection vulnerability.
Description
The remote host seems to be running OpenBB, a forum management system.
There is a bug which allows an attacker to inject SQL command when passing a single quote (') to the CID argument of the file index.php, as in : GET /index.php?CID='<sql query>
An attacker may use this flaw to gain credentials or to modify your database.
Solution
If the remote host is running OpenBB, upgrade to the latest version
Plugin Details
File Name: openbb_sql_injection.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Vulnerability Publication Date: 4/25/2003
Reference Information
BID: 7401