newsbot
04-12-2007, 11:03 PM
Beehive Forum (http://www.beehiveforum.net/) is "an open source web based forum application written in PHP". A vulnerability exists in the Beehive Forum software that could allow a remote user to execute SQL injection attacks. These attacks could compromise sensitive data including usernames and passwords for the Beehive application. Arbitrary data from other applications hosted on the same server could also be compromised, depending on the configuration of MySQL.
http://www.securiteam.com/unixfocus/6J00115KKS.html
http://www.securiteam.com/unixfocus/6J00115KKS.html