TinyPHPForum Multiple Directory Traversal Vulnerabilities
BID:16163
Info
TinyPHPForum Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 16163 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2006 12:00AM |
| Updated: | Jan 06 2006 12:00AM |
| Credit: | Aliaksandr Hartsuyeu is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
TinyPHPForum TinyPHPForum 3.6 |
| Not Vulnerable: | |
Discussion
TinyPHPForum Multiple Directory Traversal Vulnerabilities
TinyPHPForum is prone to multiple directory traversal vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the Web server process. Information obtained may aid in further attacks; other attacks are also possible.
These issues are reported to affect version 3.6; earlier versions may also be vulnerable.
TinyPHPForum is prone to multiple directory traversal vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the Web server process. Information obtained may aid in further attacks; other attacks are also possible.
These issues are reported to affect version 3.6; earlier versions may also be vulnerable.
Exploit / POC
TinyPHPForum Multiple Directory Traversal Vulnerabilities
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/tpf/profile.php?action=view&uname=../../username
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/tpf/profile.php?action=view&uname=../../username
Solution / Fix
TinyPHPForum Multiple Directory Traversal Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
TinyPHPForum Multiple Directory Traversal Vulnerabilities
References:
References:
- TinyPHPForum Homepage (TinyPHPForum)
- TinyPHPForum Multiple Vulnerabilities (eVuln)