PHPBB2 'phpbb_root_path' Remote File Include Vulnerability
BID:4380
Info
PHPBB2 'phpbb_root_path' Remote File Include Vulnerability
| Bugtraq ID: | 4380 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2002 12:00AM |
| Updated: | Mar 17 2002 12:00AM |
| Credit: | This issue was reported to the phpBB Group by <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 2.0 RC3 phpBB Group phpBB 2.0 RC2 phpBB Group phpBB 2.0 RC1 phpBB Group phpBB 2.0 Beta 1 |
| Not Vulnerable: |
phpBB Group phpBB 2.0 RC4 |
Discussion
PHPBB2 'phpbb_root_path' Remote File Include Vulnerability
phpBB2 is free, open-source web forums software that is written in PHP and backended by a number of database products. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
A problem has been discovered in phpBB2 which may enable an attacker to include an arbitrary attacker-supplied file which is located on a remote host. An attacker may exploit this issue by supplying the location of a remote file as the value for the 'phpbb_root_path' URL parameter.
In the case that the remote file is a PHP script, this may allow commands to be executed remotely with the privileges of the webserver. This is especially a concern for hosts running Microsoft Windows operating systems, as webservers are generally run with SYSTEM privileges on these platforms.
phpBB2 is free, open-source web forums software that is written in PHP and backended by a number of database products. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
A problem has been discovered in phpBB2 which may enable an attacker to include an arbitrary attacker-supplied file which is located on a remote host. An attacker may exploit this issue by supplying the location of a remote file as the value for the 'phpbb_root_path' URL parameter.
In the case that the remote file is a PHP script, this may allow commands to be executed remotely with the privileges of the webserver. This is especially a concern for hosts running Microsoft Windows operating systems, as webservers are generally run with SYSTEM privileges on these platforms.
Exploit / POC
PHPBB2 'phpbb_root_path' Remote File Include Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHPBB2 'phpbb_root_path' Remote File Include Vulnerability
Solution:
This issue has been addressed in phpBB2 RC4. Affected users are advised to upgrade.
phpBB Group phpBB 2.0 Beta 1
phpBB Group phpBB 2.0 RC1
phpBB Group phpBB 2.0 RC3
phpBB Group phpBB 2.0 RC2
Solution:
This issue has been addressed in phpBB2 RC4. Affected users are advised to upgrade.
phpBB Group phpBB 2.0 Beta 1
-
phpBB Group phpBB-2.0-RC4.tar.gz
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0-RC4.tar.gz
phpBB Group phpBB 2.0 RC1
-
phpBB Group phpBB-2.0-RC4.tar.gz
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0-RC4.tar.gz
phpBB Group phpBB 2.0 RC3
-
phpBB Group phpBB-2.0-RC4.tar.gz
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0-RC4.tar.gz
phpBB Group phpBB 2.0 RC2
-
phpBB Group phpBB-2.0-RC4.tar.gz
http://prdownloads.sourceforge.net/phpbb/phpBB-2.0-RC4.tar.gz