Invision Power Board Insecure Permissions Vulnerability
BID:8737
Info
Invision Power Board Insecure Permissions Vulnerability
| Bugtraq ID: | 8737 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 30 2003 12:00AM |
| Updated: | Sep 30 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to f3rm0r. |
| Vulnerable: |
Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 |
| Not Vulnerable: | |
Discussion
Invision Power Board Insecure Permissions Vulnerability
Invision Power Board has been reported prone to a configuration issue that could allow attackers with local interactive access to modify Invision Power Board source files. The issue has been reported to present itself because Invision Power Board does not correctly set permissions on folders during the installation process. Any local user who is a member of the same group as Invision Power Board may make modifications to Invision Power Board source files.
Invision Power Board has been reported prone to a configuration issue that could allow attackers with local interactive access to modify Invision Power Board source files. The issue has been reported to present itself because Invision Power Board does not correctly set permissions on folders during the installation process. Any local user who is a member of the same group as Invision Power Board may make modifications to Invision Power Board source files.
Exploit / POC
Invision Power Board Insecure Permissions Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Invision Power Board Insecure Permissions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Invision Power Board Insecure Permissions Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)