Contact: Web / Voice / Email / Tips
Simple Thoughts Blog - Java and Web Technologies

Simple solutions for complex problems.

 

phpBB Auction Module Vulnerable To File Inclusion Exploit

May 3rd, 2006 by Angsuman Chakraborty

Input passed to the “phpbb_root_path” parameter in “auction/auction_common.php” isn’t properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.

The vulnerability, discovered by VietMafia, has been confirmed in version 1.3m. Other versions may also be affected.

Protection / Solution
1. Disable “register_globals”
2. Edit the source code to ensure that input is properly verified.

via Pridels


Filed under Computer Security, Open Source Software, PHP, Web, Web Hosting, Web Services | | RSS 2.0 | Trackback this Article | Email this Article

You may also like to read

»Free Forum Software (PHP, MySQL); Alternative to phpBB
»Mambo CMS Suffers From File Inclusion Vulnerability
»How To Fix phpBB Error - The submitted form was invalid. Try submitting again.
»Apache HTTPD: How To Turn Off Index Listing in Directory & Sub-Directories; Protect WordPress wp-content
»BandSite CMS and SmartSite CMS (PHP based) Root File Inclusion Vulnerability Discovered
»PHP XMLRPC Remote Code Execution Vulnerability affecting Popular Blogging and CMS Platforms like WordPress 1.5.1.2 (and lower), PostNuke, Drupal, b2evolution TikiWiki etc.
»Absolutebusy Web CRM Embraces Tagging
»Xoops CMS SQL Injection Vulnerability Reported
»Google Happy Loser in Wireless Spectrum Licenses
»Watermarked Blank 5 Rs Indian Bank Notes On Auction
»Cross-Site Scripting Vulnerability in Apache mod_imap Module
»Command Execution Vulnerability in WordPress Affecting all Versions
»How To Enable / Use .htaccess / Nice permalinks in Apache Web Server on Windows
»iPhone Hacking: Security Vulnerability Allows Full Remote Control From Malicious Web Sites
»Program (Source Code) to Trim Whitespaces from Files...

Looking forward to hear your thoughts.



Please enter the code shown below ( to verify that you are human ) before you click Submit Comment.

No. 1 method to ethically increase your blog traffic and reach.

Translate

Translate to EnglishÜbersetzen Sie zum Deutsch/GermanPřeložit do Čech/CzechOversætte hen til Dansk/DanishKääntää jotta Finnish/FinnishLefordít -hoz Magyar/HungarianÞýða til Íslenska/IcelandicTraducir a Latinoamericano Español/Latin American Spanishtagapagsalin sa Filipino/FilipinoTłumaczyć wobec Polski/PolishA traduce la spre Român/RomanianPrevesti za Srpski/Serbiantolmačiti v slovenski/SlovenianÖversätta till Svensk/SwedishChyfieitha at Cymraeg/Welshtercüme etmek -e doğru Türk/TurkishPrevesti to Hrvatski/CroatianПревеждам към Българин/BulgarianTraduzca al Español/SpanishTraduisez au Français/FrenchTraduca ad Italiano/ItalianTraduza ao Português/Portuguese日本語に翻訳しなさい /Japanese한국어에게 번역하십시오/Korean中文翻译/Chinese Simplifiedترجمة الى العربية/ArabicVertaal aan het Nederlands/DutchΜεταφράστε στα ελληνικά/GreekПереведите к русскому/RussianOversetter til Norsk/Norwegian中文翻译/Chinese TraditionalTraduzir a Língua portuguesa brasileira/Brazilian PortugueseReddo ut Latin/Latin

Taragana Network

»Ctrl-S
»Enterprise Blog
»Free Book on Eye Care by Natural Therapy
»Health Care Blog
»Hot Computer Jobs Blog
»Pet Care & Grooming News and Tips
»Phil Law Blog
»Taragana - Software Outsourcing
»The Angsuman Chakraborty Blog
»The Diabetes Cure Blog
»The Eye Treatment Blog
»The Stem Cell Blog
»Weblog Hosting Blog
"The eternal mystery of the world is its comprehensibility." - Albert Einstein