Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Full Disclosure: Re: Security Advisory - phpBB 2.0.15 PHP-code injection bug

Re: Security Advisory - phpBB 2.0.15 PHP-code injection bug

From: Siegfried <siegfri3d_at_gmail.com>
Date: Wed, 29 Jun 2005 18:28:10 +0200

>Due to a bug in the phpBB highlighting code it's possible to inject
>PHP-code into the running script. E.g. It's possible to run system
>commands if the PHP interpreter allows system() and simular functions.
>This is actually based on an old bug which was improperly fixed in
>phpBB 2.0.11.

phpBB versions 2.0.11 through 2.0.14 don't seem affected no? it was
rather reintroduced in version 2.0.15 because they changed some things
in this part of the code
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Jun 29 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]