freeForum Remote PHP Script Code Injection Vulnerability
BID:16871
Info
freeForum Remote PHP Script Code Injection Vulnerability
| Bugtraq ID: | 16871 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2006 12:00AM |
| Updated: | Feb 28 2006 12:00AM |
| Credit: | Aliaksandr Hartsuyeu is credited with the discovery of this issue. |
| Vulnerable: |
freeForum freeForum 1.2 |
| Not Vulnerable: |
freeForum freeForum 1.2.1 |
Discussion
freeForum Remote PHP Script Code Injection Vulnerability
freeForum is prone to a remote PHP script code-injection vulnerability.
An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.
freeForum version 1.2 is vulnerable to these issues; other versions may also be affected.
freeForum is prone to a remote PHP script code-injection vulnerability.
An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.
freeForum version 1.2 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
freeForum Remote PHP Script Code Injection Vulnerability
This issue can be exploited through use of a web client.
This issue can be exploited through use of a web client.
Solution / Fix
freeForum Remote PHP Script Code Injection Vulnerability
Solution:
The vendor has released version 1.2.1 to address this issue.
freeForum freeForum 1.2
Solution:
The vendor has released version 1.2.1 to address this issue.
freeForum freeForum 1.2
-
freeForum freeforum-1.2.1.tgz
http://soft.zoneo.net/freeForum/Files/get.php?freeforum-1.2.1.tgz
References
freeForum Remote PHP Script Code Injection Vulnerability
References:
References:
- freeForum Home Page (freeForum)
- FreeForum PHP Code Execution & Multiple XSS Vulnerabilities (eVuln.com)