8166109 2002-03-18 16:47 +0000 /25 rader/ nullbyte <nullbyte@inetd-secure.net> Sänt av: joel@lysator.liu.se Importerad: 2002-03-20 01:12 av Brevbäraren Extern mottagare: bugtraq@securityfocus.com Extern kopiemottagare: vuln-dev@securityfocus.com Mottagare: Bugtraq (import) <21489> Ärende: phpBB2 remote execution command ------------------------------------------------------------ From: nullbyte <nullbyte@inetd-secure.net> To: bugtraq@securityfocus.com Cc: vuln-dev@securityfocus.com Message-ID: <Pine.BSF.4.44.0203181645580.19291-101000@inetd-secure.net> phpBB2 is vulnerable to remote execution command All *nix running phpBB2 versoion 2.0. Bug could be found at "phpBB2 root path" which is allowed remote attacker to execute any command remotely. The vulnerability of this attack start with '/phpBB2/includes/db.php?phpbb_root_path=' but some backdoor server are needed to launch the attack. I did not look further into this bug. It is tested on most *nix systems running phpBB2 version 2.0. Probably all versions. Bug was found by pokley and nullbyte nullbyte nullbyte@inetd-secure.net (8166109) /nullbyte <nullbyte@inetd-secure.net>/(Ombruten) Bilaga (application/octet-stream) i text 8166110 Kommentar i text 8172819 av Nathan Anderson <nathan@andersonsplace.net> 8166110 2002-03-18 16:47 +0000 /11 rader/ nullbyte <nullbyte@inetd-secure.net> Bilagans filnamn: "phpBB2.tar.gz" Importerad: 2002-03-20 01:12 av Brevbäraren Extern mottagare: bugtraq@securityfocus.com Extern kopiemottagare: vuln-dev@securityfocus.com Mottagare: Bugtraq (import) <21490> Bilaga (text/plain) till text 8166109 Ärende: Bilaga (phpBB2.tar.gz) till: phpBB2 remote execution command ------------------------------------------------------------ <