SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#920931

phpBB does not adequately validate user input for language selection thereby allowing user to execute arbitrary php code

Overview

phpBB is an open-source bulletin board program. A user input validation problem exists with regard to language settings. An intruder can excute arbitrary php code and gain a shell with the privileges of the web server on the system.

I. Description

Version 1.4.0 and earlier have a user input validation problem that can lead to the execution of arbitrary php code. The remote user can specify what language they would like to use and phpBB will set several critical variables based on the language file loaded. If a user specifies a non-existant language, phpBB does not check if the input is valid and no language file is loaded. The intruder can use a specially crafted URL to set the variables that should have been set by the language file. The variables are then processed by eval() and the intruder's php code is executed.

II. Impact

An intruder can excute arbitrary php code and gain a shell with the privileges of the web server on the system.

III. Solution

Upgrade to phpBB version 1.4.1.

Systems Affected

VendorStatusDate NotifiedDate Updated
PHPBBVulnerable16-Aug-2001

References


http://www.securityfocus.com/bid/3167
http://sourceforge.net/project/shownotes.php?release_id=46274
http://phpBB.sourceforge.net/phpBB/

Credit

This vulnerability was discovered by kill-9 <kill-9@modernhackers.com>.

This document was written by Jason Rafail.

Other Information

Date Public:2001-08-03
Date First Published:2001-09-10
Date Last Updated:2001-09-13
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:17.21
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader