Nilehoster Topics Viewer Multiple SQL Injection and Local File Include Vulnerabilities
17 Jun. 2012
Summary
Nilehoster Topics Viewer is prone to multiple SQL-injection vulnerabilities and a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit these vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. By using directory-traversal strings to execute local script code in the context of the application, the attacker may be able to obtain sensitive information that may aid in further attacks.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.