Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Multiple vulnerabilities in phpBB 2.0.13 and older


Vulnerability Assessment Details

Multiple vulnerabilities in phpBB 2.0.13 and older

Vulnerability Assessment Summary
Checks for multiple vulnerabilities in phpBB 2.0.13 and older

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP application that is affected by
multiple vulnerabilities.

Description :

According to its banner, the remote host is running a version of phpBB
that suffers from multiple flaws:

- A Path Disclosure Vulnerability
A remote attacker can cause phpBB to reveal its installation
path via a direct request to the script 'db/oracle.php'.

- A Cross-Site Scripting Vulnerability
The application does not properly sanitize user input before
using it in 'privmsg.php' and 'viewtopic.php'.

- A Privilege Escalation Vulnerability
In 'session.php' phpBB resets the 'user_id' value when an
autologin fails
it does not, however, reset the 'user_level'
value, which remains as the account that failed the autologin.
Since the software uses the 'user_level' parameter in some
cases to control access to privileged functionality, this flaw
permits a possible hacker to view information, and possibly even
perform tasks, normally limited to administrators.

- SQL Injection Vulnerabilities
The DLMan Pro and LinksLinks Pro mods, if installed, reportedly
fail to properly sanitize user input to the 'file_id' parameter
of the 'dlman.php' script and the 'id' parameter of the
'links.php' script respectively before using it in an SQL
query. This may permit a possible hacker to pass malicious input
to database queries.

See also :

http://archives.neohapsis.com/archives/bugtraq/2005-03/0059.html
http://archives.neohapsis.com/archives/bugtraq/2005-03/0085.html
http://archives.neohapsis.com/archives/bugtraq/2005-04/0056.html
http://archives.neohapsis.com/archives/bugtraq/2005-04/0063.html

Solution :

Upgrade to a version after phpBB 2.0.13 and disable the DLMan Pro and
LinksLinks Pro mods.

Network Security Threat Level:

Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)

Networks Security ID: 12736, 13028, 13030

Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2006 Tenable Network Security

Cables, Connectors


For Lenovo ideaPad Flex 5-14IIL05 5-14ARE 5-14ITL05 Palmrest Keyboard 5CB0Y85490 picture

For Lenovo ideaPad Flex 5-14IIL05 5-14ARE 5-14ITL05 Palmrest Keyboard 5CB0Y85490

$73.79



For Lenovo IdeaPad 1 15ADA7 15AMN7 LCD Back Cover Hinge Cover Bezel 5CB1F36621 picture

For Lenovo IdeaPad 1 15ADA7 15AMN7 LCD Back Cover Hinge Cover Bezel 5CB1F36621

$74.24



For Lenovo IdeaPad Gaming 3-15IHU6 15ACH6 Palmrest Keyboard Touchpad 5CB1D04600 picture

For Lenovo IdeaPad Gaming 3-15IHU6 15ACH6 Palmrest Keyboard Touchpad 5CB1D04600

$118.58



Lenovo IP 5 16IAU7 16

Lenovo IP 5 16IAU7 16" 2.5K Chromebook i3-1215U 8GB Ram 128GB eMMC Chrome OS

$219.99



Lenovo Ideapad 1i 15.6

Lenovo Ideapad 1i 15.6" FHD Notebook Intel Core i5-1235U 8GB RAM 256GB SSD

$339.99



Lenovo Loq 15Irh8 15

Lenovo Loq 15Irh8 15" Laptop Core i5-13420H GeForce RTX 2050 16GB 512GB SSD W11H

$519.99



Lenovo Legion Pro 5i 16

Lenovo Legion Pro 5i 16" Gaming Laptop RTX 4070 8GB i9-13900HX 16GB RAM 1TB SSD

$1399.99



Lenovo LOQ Laptop, 15.6

Lenovo LOQ Laptop, 15.6" FHD IPS 144Hz, i5-13450HX, 12GB, 512GB SSD

$728.99



Lenovo Thinkpad T470 14'' (256GB SSD Intel Core i5-7300U 2.6GHz 8GB RAM) Laptop picture

Lenovo Thinkpad T470 14'' (256GB SSD Intel Core i5-7300U 2.6GHz 8GB RAM) Laptop

$100.00



Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 512GB SSD Windows 10 picture

Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 512GB SSD Windows 10

$276.73



Discussions

No Discussions have been posted on this vulnerability.