PHPBB BBCode IMG Tag Script Injection Vulnerability
BID:14555
Info
PHPBB BBCode IMG Tag Script Injection Vulnerability
| Bugtraq ID: | 14555 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2005 12:00AM |
| Updated: | Aug 12 2005 12:00AM |
| Credit: | Easyex is credited with the discovery of this vulnerability. |
| Vulnerable: |
VBulletin VBulletin 3.0.7 PunBB PunBB 1.2.6 phpBB Group phpBB 2.0.17 |
| Not Vulnerable: | |
Discussion
PHPBB BBCode IMG Tag Script Injection Vulnerability
phpBB is prone to a script injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input in bbcode '[IMG]' tags included in a user signature.
Successful exploitation of this vulnerability could permit the injection of arbitrary HTML or script code into the browser of an unsuspecting user in the context of the affected site.
This issue is reported to affect phpBB version 2.0.17; earlier versions may also be vulnerable.
This issue reportedly affects other applications utilizing bbcode. Currently vBulletin is also known to be affected by this vulnerability. This issue also affects punBB 1.2.6; other versions may also be vulnerable.
phpBB is prone to a script injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input in bbcode '[IMG]' tags included in a user signature.
Successful exploitation of this vulnerability could permit the injection of arbitrary HTML or script code into the browser of an unsuspecting user in the context of the affected site.
This issue is reported to affect phpBB version 2.0.17; earlier versions may also be vulnerable.
This issue reportedly affects other applications utilizing bbcode. Currently vBulletin is also known to be affected by this vulnerability. This issue also affects punBB 1.2.6; other versions may also be vulnerable.
Exploit / POC
PHPBB BBCode IMG Tag Script Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHPBB BBCode IMG Tag Script Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPBB BBCode IMG Tag Script Injection Vulnerability
References:
References:
- BBCode [IMG] [/IMG ] Tag Vulnerability (h4cky0u)
- PhpBB - [img][/img] vulnerability (Dark Assasins)
- PunBB Homepage (PunBB)
- vBulletin BBCode IMG Tag Script Injection Vulnerability (y3dips)
- Vendor Homepage (Kyberna)
- PunBB BBCode IMG Tag Script Injection Vulnerability ([email protected])