Flat PHP Board Multiple Remote Vulnerabilities
BID:26782
Info
Flat PHP Board Multiple Remote Vulnerabilities
| Bugtraq ID: | 26782 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6232 CVE-2007-6395 CVE-2007-6396 CVE-2007-6397 CVE-2007-6398 CVE-2007-6399 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | KiNgOfThEwOrLd discovered these vulnerabilities. |
| Vulnerable: |
Flat PHP Board Flat PHP Board 1.2 |
| Not Vulnerable: | |
Discussion
Flat PHP Board Multiple Remote Vulnerabilities
Flat PHP Board is prone to multiple remote vulnerabilities, including remote arbitrary-code-execution, file-include, security-bypass, and information-disclosure issues.
Exploiting these issues may allow an attacker to compromise the application and a webserver hosting the vulnerable software; other attacks are also possible.
These issues affect Flat PHP Board 1.2 and prior versions.
Flat PHP Board is prone to multiple remote vulnerabilities, including remote arbitrary-code-execution, file-include, security-bypass, and information-disclosure issues.
Exploiting these issues may allow an attacker to compromise the application and a webserver hosting the vulnerable software; other attacks are also possible.
These issues affect Flat PHP Board 1.2 and prior versions.
Exploit / POC
Flat PHP Board Multiple Remote Vulnerabilities
An attacker can exploit these issues via a browser.
The following proof-of-concept URI is available for the information-disclosure issue:
http://www.example.com/users/[target_username].php
The following proof-of-concept URIs are available for the local file-include issues:
http://www.example.com/index.php?a=topic&topic=../[arbitrary php file]
http://www.example.com/index.php?a=viewprofile&username=../ [arbitrary php file]
The following proof-of-concept is available for the code-execution issue:
An attacker can exploit these issues via a browser.
The following proof-of-concept URI is available for the information-disclosure issue:
http://www.example.com/users/[target_username].php
The following proof-of-concept URIs are available for the local file-include issues:
http://www.example.com/index.php?a=topic&topic=../[arbitrary php file]
http://www.example.com/index.php?a=viewprofile&username=../ [arbitrary php file]
The following proof-of-concept is available for the code-execution issue:
Solution / Fix
Flat PHP Board Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Flat PHP Board Multiple Remote Vulnerabilities
References:
References:
- Flat PHP Board <= 1.2 Multiple Vulnerabilities (KiNgOfThEwOrLd)