VBulletin Misc.PHP Arbitrary PHP Script Code Execution Vulnerability
BID:12622
Info
VBulletin Misc.PHP Arbitrary PHP Script Code Execution Vulnerability
| Bugtraq ID: | 12622 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0511 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2005 12:00AM |
| Updated: | Jul 12 2009 10:56AM |
| Credit: | Discovery of this vulnerability is credited to pokley <[email protected]>. |
| Vulnerable: |
VBulletin VBulletin 3.0.6 VBulletin VBulletin 3.0.5 VBulletin VBulletin 3.0.4 VBulletin VBulletin 3.0.3 VBulletin VBulletin 3.0.2 VBulletin VBulletin 3.0.1 VBulletin VBulletin 3.0 Gamma VBulletin VBulletin 3.0 beta 7 VBulletin VBulletin 3.0 beta 6 VBulletin VBulletin 3.0 beta 5 VBulletin VBulletin 3.0 beta 4 VBulletin VBulletin 3.0 beta 3 VBulletin VBulletin 3.0 beta 2 VBulletin VBulletin 3.0 VBulletin VBulletin 2.3.4 VBulletin VBulletin 2.3.3 VBulletin VBulletin 2.3.2 VBulletin VBulletin 2.3 .0 VBulletin VBulletin 2.2.9 VBulletin VBulletin 2.2.8 VBulletin VBulletin 2.2.7 VBulletin VBulletin 2.2.6 VBulletin VBulletin 2.2.5 VBulletin VBulletin 2.2.4 VBulletin VBulletin 2.2.3 VBulletin VBulletin 2.2.2 VBulletin VBulletin 2.2.1 VBulletin VBulletin 2.2 .0 VBulletin VBulletin 2.0.3 VBulletin VBulletin 2.0 rc 3 VBulletin VBulletin 2.0 rc 2 VBulletin VBulletin 1.0.1 lite |
| Not Vulnerable: |
VBulletin VBulletin 3.0.7 |
Discussion
VBulletin Misc.PHP Arbitrary PHP Script Code Execution Vulnerability
vBulletin is reported prone to an arbitrary PHP script code execution vulnerability. The issue is reported to exist due to a lack of sufficient input sanitization performed on user-supplied data before this data is included in a dynamically generated script.
This vulnerability is reported to affect vBulletin board versions up to and including 3.0.6 that are configured with 'Add Template Name in HTML Comments' functionality enabled.
vBulletin is reported prone to an arbitrary PHP script code execution vulnerability. The issue is reported to exist due to a lack of sufficient input sanitization performed on user-supplied data before this data is included in a dynamically generated script.
This vulnerability is reported to affect vBulletin board versions up to and including 3.0.6 that are configured with 'Add Template Name in HTML Comments' functionality enabled.
Exploit / POC
VBulletin Misc.PHP Arbitrary PHP Script Code Execution Vulnerability
The following example is available:
http://www.example.com/misc.php?do=page&template={${phpinfo()}}
An exploit (php_vbulletin_template.pm) for the Metasploit Framework is available.
The following example is available:
http://www.example.com/misc.php?do=page&template={${phpinfo()}}
An exploit (php_vbulletin_template.pm) for the Metasploit Framework is available.
Solution / Fix
VBulletin Misc.PHP Arbitrary PHP Script Code Execution Vulnerability
Solution:
The vendor has released vBulletin version 3.0.7 to address this issue:
VBulletin VBulletin 1.0.1 lite
VBulletin VBulletin 2.0 rc 2
VBulletin VBulletin 2.0 rc 3
VBulletin VBulletin 2.0.3
VBulletin VBulletin 2.2 .0
VBulletin VBulletin 2.2.1
VBulletin VBulletin 2.2.2
VBulletin VBulletin 2.2.3
VBulletin VBulletin 2.2.4
VBulletin VBulletin 2.2.5
VBulletin VBulletin 2.2.6
VBulletin VBulletin 2.2.7
VBulletin VBulletin 2.2.8
VBulletin VBulletin 2.2.9
VBulletin VBulletin 2.3 .0
VBulletin VBulletin 2.3.2
VBulletin VBulletin 2.3.3
VBulletin VBulletin 2.3.4
VBulletin VBulletin 3.0 beta 4
VBulletin VBulletin 3.0 beta 2
VBulletin VBulletin 3.0 beta 6
VBulletin VBulletin 3.0 beta 7
VBulletin VBulletin 3.0 Gamma
VBulletin VBulletin 3.0 beta 3
VBulletin VBulletin 3.0 beta 5
VBulletin VBulletin 3.0
VBulletin VBulletin 3.0.1
VBulletin VBulletin 3.0.2
VBulletin VBulletin 3.0.3
VBulletin VBulletin 3.0.4
VBulletin VBulletin 3.0.5
VBulletin VBulletin 3.0.6
Solution:
The vendor has released vBulletin version 3.0.7 to address this issue:
VBulletin VBulletin 1.0.1 lite
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.0 rc 2
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.0 rc 3
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.0.3
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2 .0
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.1
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.2
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.3
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.4
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.5
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.6
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.7
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.8
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.2.9
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.3 .0
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.3.2
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.3.3
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 2.3.4
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 beta 4
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 beta 2
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 beta 6
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 beta 7
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 Gamma
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 beta 3
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0 beta 5
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0.1
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0.2
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0.3
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0.4
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0.5
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
VBulletin VBulletin 3.0.6
-
VBulletin vBulletin 3.0.7
http://www.vbulletin.com/forum/showthread.php?postid=819562
References
VBulletin Misc.PHP Arbitrary PHP Script Code Execution Vulnerability
References:
References:
- vBulletin 3.0.7 Released - Security Patch (VBulletin)