SIR GNUBoard Multiple Remote Vulnerabilities
BID:33538
Info
SIR GNUBoard Multiple Remote Vulnerabilities
| Bugtraq ID: | 33538 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2009 12:00AM |
| Updated: | Feb 02 2009 08:09PM |
| Credit: | [email protected] |
| Vulnerable: |
SIR GNUBoard 4.31.4 SIR GNUBoard 4.31.3 |
| Not Vulnerable: | |
Discussion
SIR GNUBoard Multiple Remote Vulnerabilities
SIR GNUBoard is prone to a local file-include vulnerability, an SQL-injection vulnerability, and an information-disclosure vulnerability.
Attackers can exploit these issues to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or learn the location of uploaded files. Further attacks may be possible when these issues are combined.
GNUBoard 4.31.04 is vulnerable; other versions may also be affected.
SIR GNUBoard is prone to a local file-include vulnerability, an SQL-injection vulnerability, and an information-disclosure vulnerability.
Attackers can exploit these issues to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or learn the location of uploaded files. Further attacks may be possible when these issues are combined.
GNUBoard 4.31.04 is vulnerable; other versions may also be affected.
Exploit / POC
SIR GNUBoard Multiple Remote Vulnerabilities
An attacker can exploit these issues with a browser.
The following example URI is available for the local-file-include issue:
http://www.example.com/GnuBoard/bbs/poll_result.php?po_id=177&skin_dir=../../../../../../../../etc/passwd%00
The following example input is available for the SQL-injection issue:
mb_id = admin' or 1=1#
The following exploit is available for the information-disclosure issue:
An attacker can exploit these issues with a browser.
The following example URI is available for the local-file-include issue:
http://www.example.com/GnuBoard/bbs/poll_result.php?po_id=177&skin_dir=../../../../../../../../etc/passwd%00
The following example input is available for the SQL-injection issue:
mb_id = admin' or 1=1#
The following exploit is available for the information-disclosure issue:
Solution / Fix
SIR GNUBoard Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].