YaBB Forum Profile CRLF Injection Remote Privilege Escalation Vulnerability
BID:24455
Info
YaBB Forum Profile CRLF Injection Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 24455 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3208 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Peter Vreugdenhil is credited with the discovery of this vulnerability. |
| Vulnerable: |
YaBB YaBB 2.1 |
| Not Vulnerable: | |
Discussion
YaBB Forum Profile CRLF Injection Remote Privilege Escalation Vulnerability
YaBB Forum is prone to a remote privilege-escalation vulnerability because the application fails to properly sanitize user-supplied input before writing it to a configuration file.
Successfully exploiting this issue allows remote attackers to gain administrative privileges in the web application and to execute arbitrary Perl script code in the context of the hosting webserver. This may facilitate the remote compromise of affected computers.
YaBB Forum 2.1 is vulnerable to this issue; other versions may also be affected.
YaBB Forum is prone to a remote privilege-escalation vulnerability because the application fails to properly sanitize user-supplied input before writing it to a configuration file.
Successfully exploiting this issue allows remote attackers to gain administrative privileges in the web application and to execute arbitrary Perl script code in the context of the hosting webserver. This may facilitate the remote compromise of affected computers.
YaBB Forum 2.1 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
YaBB Forum Profile CRLF Injection Remote Privilege Escalation Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
YaBB Forum Profile CRLF Injection Remote Privilege Escalation Vulnerability
Solution:
The vendor has released a fix for this issue. Please see the references for more information.
YaBB YaBB 2.1
Solution:
The vendor has released a fix for this issue. Please see the references for more information.
YaBB YaBB 2.1
-
YaBB Security_Patch_05-24-07.zip
http://www.yabbforum.com/yabbfiles/Attachments/Security_Patch_05-24-07 .zip
References
YaBB Forum Profile CRLF Injection Remote Privilege Escalation Vulnerability
References:
References: