PHP-Post Multiple Remote Input Validation Vulnerabilities
BID:12845
Info
PHP-Post Multiple Remote Input Validation Vulnerabilities
| Bugtraq ID: | 12845 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0831 CVE-2005-0832 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2005 12:00AM |
| Updated: | Mar 27 2008 06:19PM |
| Credit: | PHOX is credited with disclosing the username spoofing issue. The cross-site scripting issues were reported by the vendor. |
| Vulnerable: |
PHP-post Web Forum 0.32 PHP-post Web Forum 0.22 PHP-post Web Forum 0.21 PHP-post Web Forum 0.3 PHP-post Web Forum 0.2 PHP-post Web Forum 0.1 |
| Not Vulnerable: |
PHP-post Web Forum 0.33 |
Discussion
PHP-Post Multiple Remote Input Validation Vulnerabilities
Multiple remote input-validation vulnerabilities affect PHP-Post. These issues occur because the application fails to properly sanitize user-supplied input before including it in critical site functionality.
The issues reported are multiple unspecified cross-site scripting vulnerabilities and a username-spoofing issue.
An attacker may leverage these issues to execute arbitrary code in the browsers of unsuspecting users and to spoof previously registered usernames.
Multiple remote input-validation vulnerabilities affect PHP-Post. These issues occur because the application fails to properly sanitize user-supplied input before including it in critical site functionality.
The issues reported are multiple unspecified cross-site scripting vulnerabilities and a username-spoofing issue.
An attacker may leverage these issues to execute arbitrary code in the browsers of unsuspecting users and to spoof previously registered usernames.
Exploit / POC
PHP-Post Multiple Remote Input Validation Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
PHP-Post Multiple Remote Input Validation Vulnerabilities
Solution:
The vendor has released PHP-Post 0.33 to address this issue. Please see the references for more information.
PHP-post Web Forum 0.1
PHP-post Web Forum 0.2
PHP-post Web Forum 0.21
PHP-post Web Forum 0.22
PHP-post Web Forum 0.3
PHP-post Web Forum 0.32
Solution:
The vendor has released PHP-Post 0.33 to address this issue. Please see the references for more information.
PHP-post Web Forum 0.1
-
PHP-Post PHP-Post 0.33
http://www.php-post.co.uk/files/phpp.zip
PHP-post Web Forum 0.2
-
PHP-Post PHP-Post 0.33
http://www.php-post.co.uk/files/phpp.zip
PHP-post Web Forum 0.21
-
PHP-Post PHP-Post 0.33
http://www.php-post.co.uk/files/phpp.zip
PHP-post Web Forum 0.22
-
PHP-Post PHP-Post 0.33
http://www.php-post.co.uk/files/phpp.zip
PHP-post Web Forum 0.3
-
PHP-Post PHP-Post 0.33
http://www.php-post.co.uk/files/phpp.zip
PHP-post Web Forum 0.32
-
PHP-Post PHP-Post 0.33
http://www.php-post.co.uk/files/phpp.zip
References
PHP-Post Multiple Remote Input Validation Vulnerabilities
References:
References:
- PHP-Post Download and Change Log Page (PHP-Post)
- PHP-Post Home Page (PHP-Post)
- PHP-Post Exploit (Terencentanio Enache
)