PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability
BID:6173
Info
PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability
| Bugtraq ID: | 6173 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2002 12:00AM |
| Updated: | Nov 13 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Hai Nam Luke <[email protected]>. |
| Vulnerable: |
RustyDragon phpBB Advanced Quick Reply Hack 1.1 .0 RustyDragon phpBB Advanced Quick Reply Hack 1.0 .0 |
| Not Vulnerable: | |
Discussion
PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability
The phpBB Advanced Quick Reply Hack is prone to an issue which may allow attackers to include arbitrary files from a remote server.
It is possible for remote attackers to influence the include path for 'extension.inc' in the 'quick_reply.php' script. As a result, an attacker may cause an arbitrary PHP script to be included from an attacker-supplied source, which may result in execution of commands with the privileges of the webserver.
The phpBB Advanced Quick Reply Hack is prone to an issue which may allow attackers to include arbitrary files from a remote server.
It is possible for remote attackers to influence the include path for 'extension.inc' in the 'quick_reply.php' script. As a result, an attacker may cause an arbitrary PHP script to be included from an attacker-supplied source, which may result in execution of commands with the privileges of the webserver.
Solution / Fix
PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability
References:
References:
- Advanced Quick Reply Hack Page (RustyDragon)
- Code Injection in phpBB Advanced Quick Reply Mod (Hai Nam Luke
)