PHPBB Auth.PHP File Disclosure Vulnerability
BID:6889
Info
PHPBB Auth.PHP File Disclosure Vulnerability
| Bugtraq ID: | 6889 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2003 12:00AM |
| Updated: | Feb 19 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to David Zentner <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 1.4.4 phpBB Group phpBB 1.4.2 phpBB Group phpBB 1.4.1 phpBB Group phpBB 1.4 .0 |
| Not Vulnerable: | |
Discussion
PHPBB Auth.PHP File Disclosure Vulnerability
A flaw exists in the 'auth.php' script which may allow attackers to cause local web server readable files to be disclosed or interpreted. This is due to insufficient sanitization of the null character (%00) from CGI parameters. It has been demonstrated that in some circumstances it is possible to exploit this issue to execute arbitrary PHP code with the privileges of the webserver process.
A flaw exists in the 'auth.php' script which may allow attackers to cause local web server readable files to be disclosed or interpreted. This is due to insufficient sanitization of the null character (%00) from CGI parameters. It has been demonstrated that in some circumstances it is possible to exploit this issue to execute arbitrary PHP code with the privileges of the webserver process.
Exploit / POC
PHPBB Auth.PHP File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
PHPBB Auth.PHP File Disclosure Vulnerability
Solution:
It has been reported that the vendor will not be releasing fixes for phpBB 1.4.x. Users are advised to upgrade to phpBB2, which is actively supported by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the vendor will not be releasing fixes for phpBB 1.4.x. Users are advised to upgrade to phpBB2, which is actively supported by the vendor.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPBB Auth.PHP File Disclosure Vulnerability
References:
References:
- PHPbb Security Flaws - 2003-02-18 (CGI_Shield)