mailing list archives
phpBB2 remote execution command
From: nullbyte <nullbyte () inetd-secure net>
Date: Mon, 18 Mar 2002 16:47:34 +0000 (GMT)
phpBB2 is vulnerable to remote execution command
All *nix running phpBB2 versoion 2.0.
Bug could be found at "phpBB2 root path" which is allowed remote attacker
to execute any command remotely.
The vulnerability of this attack start with
'/phpBB2/includes/db.php?phpbb_root_path=' but some backdoor server
are needed to launch the attack.
I did not look further into this bug.
It is tested on most *nix systems running phpBB2 version 2.0. Probably all
Bug was found by pokley and nullbyte
nullbyte () inetd-secure net
- phpBB2 remote execution command nullbyte (Mar 20)