Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities
BID:31268
Info
Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities
| Bugtraq ID: | 31268 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5090 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | James Bercegay of the GulfTech Security Research Team |
| Vulnerable: |
Electron Advanced Electron Forum 1.0.6 Electron Advanced Electron Forum 1.0.5 Electron Advanced Electron Forum 1.0.4 Electron Advanced Electron Forum 1.0.3 Electron Advanced Electron Forum 1.0.2 Electron Advanced Electron Forum 1.0.1 |
| Not Vulnerable: | |
Discussion
Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities
Advanced Electron Forum is prone to remote PHP code-injection vulnerabilities.
An attacker can exploit these issues to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Advanced Electron Forum is prone to remote PHP code-injection vulnerabilities.
An attacker can exploit these issues to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Exploit / POC
Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities
Attackers can exploit this issue via a browser.
The following example was provided:
[email]{${phpinfo()}}[/email]
Attackers can exploit this issue via a browser.
The following example was provided:
[email]{${phpinfo()}}[/email]
Solution / Fix
Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities
Solution:
Reports indicate that an upgrade is available, but Symantec has not confirmed this. Please contact the vendor for details.
Solution:
Reports indicate that an upgrade is available, but Symantec has not confirmed this. Please contact the vendor for details.
References
Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities
References:
References:
- Advanced Electron Forum Homepage (Electron)
- Advanced Electron Forum <= 1.0.6 Remote Code Execution (GulfTech Security Research
)