AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 08, 2009, 03:18:15 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5342 Members
Latest Member: hikslyypro
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PhpBB Alerts  |  Topic: phpBB viewtopic.php fails to properly sanitize input 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: phpBB viewtopic.php fails to properly sanitize input  (Read 868 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
phpBB viewtopic.php fails to properly sanitize input
« on: July 01, 2005, 07:42:38 PM »

Overview
phpBB contains an user input validation problem with regard to the parsing of the URL. An intruder can deface a phpBB website, execute arbitrary commands, or gain administrative privileges on a compromised bulletin board.

]I. Description
phpBB is an open-source bulletin board. A lack of input validation on the highlight parameter supplied to viewtopic.php may allow a remote attacker to execute arbitrary commands on a vulnerable server. The problem occurs because phpBB does not scan incoming URLs for malicious content when they are decoded.

We have seen reports of exploitation related to this vulnerability.

II. Impact
A remote attacker may be able to deface a phpBB website, execute arbitrary commands, or gain administrative privileges on a compromised bulletin board.


III. Solution
Update

Note that phpBB version 2.0.11 did not adequately correct this vulnerability. The phpBB Development Team has released phpBB version 2.0.16, http://www.phpbb.com/downloads.php, to fully correct this issue.

References
http://secunia.com/advisories/13239/
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240636
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PhpBB Alerts  |  Topic: phpBB viewtopic.php fails to properly sanitize input « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!