SIR GNUBoard Remote File Include Vulnerability
BID:11948
Info
SIR GNUBoard Remote File Include Vulnerability
| Bugtraq ID: | 11948 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Jeremy Bae at STG Security is credited with the discovery of this issue. |
| Vulnerable: |
SIR GNUBoard 3.39 SIR GNUBoard 3.38 SIR GNUBoard 3.37 SIR GNUBoard 3.36 SIR GNUBoard 3.35 SIR GNUBoard 3.34 SIR GNUBoard 3.33 SIR GNUBoard 3.32 SIR GNUBoard 3.31 SIR GNUBoard 3.30 |
| Not Vulnerable: |
SIR GNUBoard 3.40 |
Discussion
SIR GNUBoard Remote File Include Vulnerability
A remote file include vulnerability reportedly affects SIR GNUBoard. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an 'include()' function call.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the affected Web server. This issue will facilitate unauthorized access to the affected computer.
A remote file include vulnerability reportedly affects SIR GNUBoard. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an 'include()' function call.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the affected Web server. This issue will facilitate unauthorized access to the affected computer.
Exploit / POC
SIR GNUBoard Remote File Include Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
SIR GNUBoard Remote File Include Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue. Users are advised to contact the vendor to obtain fixed packages.
Solution:
The vendor has released an upgrade dealing with this issue. Users are advised to contact the vendor to obtain fixed packages.
References
SIR GNUBoard Remote File Include Vulnerability
References:
References: