This vulnerability has been flagged as being a Myth/Fake.
Timeline
Disclosure Date
2006-02-07
Description
GA's Forum Light has been reported to contain an SQL injection issue in the archive.asp script. Subsequent testing by SecurityTracker after the vendor disputed the issue indicates the software uses flat files to store data, not a back-end database. Therefore, the SQL injection report is incorrect and was likely diagnosed due to a vbscript parsing error.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
OSVDB:
Web Related,
Myth / Fake
Solution
The vulnerability reported is incorrect. No solution required.