Ultimate PHP Board (UPB)代码执行漏洞

Ultimate PHP Board (UPB)代码执行漏洞

漏洞ID 1107348 漏洞类型 未知
发布时间 2003-05-24 更新时间 2003-07-02
图片[1]-Ultimate PHP Board (UPB)代码执行漏洞-安全小百科CVE编号 CVE-2003-0395
图片[2]-Ultimate PHP Board (UPB)代码执行漏洞-安全小百科CNNVD-ID CNNVD-200307-014
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/22642
https://www.securityfocus.com/bid/87150
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200307-014
|漏洞详情
UltimatePHPBoard(UPB)1.9存在漏洞。远程攻击者可以在管理员执行admin_iplog.php时,借助一个User-Agent头部含有代码的HTTP请求,执行任意具有UPB管理员权限的PHP代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/7678/info

A vulnerability has been reported in Ultimate PHP Board. The problem is said to occur due to insufficient sanitization of user-supplied input before including log data into a PHP file. As a result, it may be possible for a remote attacker to execute arbitrary PHP commands within the context of the web server. The execution of these commands would only occur when an administrator chooses to view the log of forum activity via the 'admin_iplog.php' script. 

$ telnet www.target.org 80
Connected to www.target.org at 80
GET /board/index.php HTTP/1.0
User-Agent: <? phpinfo(); ?>
|受影响的产品
PHP Outburst Ultimate Php Board Upb 1.9
|参考资料

来源:BUGTRAQ
名称:20030524UPB:DiscussionBoard/Web-SiteTakeover
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=105379741528925&w;=2
来源:f0kp.iplus.ru
链接:http://f0kp.iplus.ru/bz/024.en.txt

相关推荐: Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability

Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability 漏洞ID 1102324 漏洞类型 Design Error 发布时间 2002-03-15 更新时间 2002-03-15 CVE编号…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享