EXEC exploit in phpBB - fix

From: Paul S. Owen (paul0x01_at_starstreak.net)
Date: 11/18/04

  • Next message: Conectiva Updates: "[CLA-2004:892] Conectiva Security Announcement - MySQL"
    To: <bugtraq@securityfocus.com>
    Date: Thu, 18 Nov 2004 12:33:45 -0000
    
    

    Following additional information supplied to us by a party other than
    "howdark.com" we can confirm the existence of a serious exploit in phpBB, in
    all versions below 2.0.11.

    We will not post concept of proof information given the seriousness of this
    issue. Unfortunately howdark.com group have chosen to as a personal vendetta
    against phpbb.com.

    We are preparing full, changed files and patch based releases which fix this
    issue (and several other bugs/issues). While we are testing this we urge all
    phpBB users to implement the fix given in the following announcement at
    phpbb.com:

    http://www.phpbb.com/phpBB/viewtopic.php?t=240513

    Please spread this information far and wide, all hosting providers if
    possible please inform your users. Anyone copying the howdark.com exploit
    _please_ ensure you also include details of the fix noted in the above post!

    PS: Thanks to the bugtraq moderators for moderating out a previous post of
    mine, ta muchly for that :)


  • Next message: Conectiva Updates: "[CLA-2004:892] Conectiva Security Announcement - MySQL"

    Relevant Pages

    • RE: EXEC exploit in phpBB - fix
      ... I'm neither a coder nor a security expert, but it seems to me that PNphpbb ... Is it safe to assume that the posted fix will work on PNphpbb as well, ... EXEC exploit in phpBB - fix ... Thanks to the bugtraq moderators for moderating out a previous post of ...
      (Bugtraq)
    • Re: [Full-Disclosure] New phpBB ViewTopic.php Cross Site Scripting Vulnerability (with fix)
      ... Due PHPBB.COM erased this posting without any comment here just the fix ... > Advisory Name:New phpBB ViewTopic.php Cross Site Scripting Vulnerability ... Full-Disclosure - We believe in it. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • [Fwd: phpBB 2.0.16 released]
      ... phpBB Group announces the release of phpBB 2.0.16. ... To fix this, please apply ... The Full Package contains entire phpBB2 ... Fixed bug in usercp_register.php, ...
      (Bugtraq)
    • Re: phpBB 1.4.0 bug leads to easy admin privileges
      ... phpBB 1.4.0 bug leads to easy admin privileges ... He also didn't mention a fix for the problem. ... I didn't write the code but saw it on the phpBB support forum. ...
      (Bugtraq)