gefährliche Sicherheitslücke in phpBB2.0.0
Verfasst: 02.11.2002 00:12
Zur Info:
phpBB Forum Bug in 'admin_ug_auth.php' Lets Remote Authenticated Users Gain Administrative Privileges on the Forum
SecurityTracker Alert ID: 1005495
CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
Date: Oct 29 2002
Impact: Modification of system information, User access via network
Fix Available: Yes Exploit Included: Yes Vendor Confirmed: Yes
Version(s): 2.0.0
Description: A vulnerability was reported in phpBB version 2.0.0. A remote authenticated user can gain administrative privileges on the forum.
It is reported that any remote authenticated user can POST to the admin_ug_auth.php script (which is used to set permissions). According to the report, administrative privileges are required to view the page, but the script accepts POST data without checking the user's privileges.
A demonstration exploit method is provided in the Source Message.
Impact: A remote authenticated user can set privileges and gain administrative privileges on the system.
Solution: It is reported that phpBB versions above 2.0.0 are not vulnerable. New versions are available at:
http://www.phpbb.com/downloads.php
Gruß, Erwinchen
phpBB Forum Bug in 'admin_ug_auth.php' Lets Remote Authenticated Users Gain Administrative Privileges on the Forum
SecurityTracker Alert ID: 1005495
CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
Date: Oct 29 2002
Impact: Modification of system information, User access via network
Fix Available: Yes Exploit Included: Yes Vendor Confirmed: Yes
Version(s): 2.0.0
Description: A vulnerability was reported in phpBB version 2.0.0. A remote authenticated user can gain administrative privileges on the forum.
It is reported that any remote authenticated user can POST to the admin_ug_auth.php script (which is used to set permissions). According to the report, administrative privileges are required to view the page, but the script accepts POST data without checking the user's privileges.
A demonstration exploit method is provided in the Source Message.
Impact: A remote authenticated user can set privileges and gain administrative privileges on the system.
Solution: It is reported that phpBB versions above 2.0.0 are not vulnerable. New versions are available at:
http://www.phpbb.com/downloads.php
Gruß, Erwinchen