View Full Version : phpBB Signature Insertion Vulnerbility
Ahmed
03-07-2005, 03:53 PM
Input passed in a signature is not properly sanitised before being used in "privmsg.php" and "viewtopic.php". This can be exploited to inject arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious user data is viewed.
The vulnerability has been reported in version 2.0.13. Other versions may also be affected.
For more details please visit http://secunia.com/advisories/14475/
SlAiD
04-06-2005, 11:53 AM
Hi;
What we can dot o solve this problem? phpBB dont have a 2.0.14 realase or similar.
Regards;
Rui
charles
04-06-2005, 04:42 PM
There should be a newer release that fixes this, but please contact support and they can patch your current installs (or show you how).
charles
itwanabe
04-09-2005, 11:13 PM
Gosh... use vbulletin!!! ;) But really, thats one of the reasons why i moved away from phpBB. It's open source: have a busy server, someone wants to be a jerk- ooops apached is down;(...
phpBB has so many patches for so many different exploits honestly. Just my .02-
SlAiD
04-10-2005, 04:58 AM
I dont want move.
I'm a moderator of phpBB Brasilian Team and founter of phpBB Portugal Team. :P
It have many exploits, because it's a open code. For example... Invision dont have many updates, but is paid.
itwanabe
04-11-2005, 01:28 AM
I dont want move.
I'm a moderator of phpBB Brasilian Team and founter of phpBB Portugal Team. :P
It have many exploits, because it's a open code. For example... Invision dont have many updates, but is paid.
Yeah but with open source material- thats an exploit aready. To each his own...
SlAiD
04-11-2005, 05:22 AM
To solve this vulnerability before 2.0.14 disable HTML signatures and HTML topics (administration panel > configuration).
charles
04-11-2005, 11:44 AM
Yeah but with open source material- thats an exploit aready. To each his own...
This is a GROSS over generalization. Please don't forget that 99% of your linux VPS is running on open source software that is not vulnerable or flawed.
charles
SlAiD
04-11-2005, 01:49 PM
I cant understend why people hack GLP projects... its free, ;)
ps: I use Windows.
It isnt open source. :o
SlAiD
04-14-2005, 01:35 PM
Hi.
phpBB have a real vuln.
See: a translation of my post (in my forum): here (http://translate.google.com/translate?u=http%3A%2F%2Fwww.forunsbb.com%2Fforum% 2Fviewtopic.php%3Ft%3D2708&langpair=pt%7Cen&hl=pt-PT&ie=UTF-8&oe=UTF-8&prev=%2Flanguage_tools)
Right..., phpBB users try this:
Open incluides/sessions.php
Fint: $userdata['user_id'] = ANONYMOUS;
In the next line, put: $userdata['user_level'] = USER;
And again... (twice)
PS: may i post the exploit here? :D
Bogdan
04-16-2005, 03:35 AM
There is already a new version that should fix those problems:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=281963
PvUtrix
04-16-2005, 12:57 PM
Yep, can be downloaded here -
http://www.phpbb.com/downloads.php
arazzz
04-18-2005, 05:44 AM
This is a GROSS over generalization. Please don't forget that 99% of your linux VPS is running on open source software that is not vulnerable or flawed.
charles
I have to aggree 100% with you, Charles. Even more - closed code is a security flaw #1 in my opinion. Just look at encryption software which has 100% open and publically available algorythms. Closed code = 100% vulnerable code...
Just my 2c.
itwanabe
04-25-2005, 12:33 AM
This is a GROSS over generalization. Please don't forget that 99% of your linux VPS is running on open source software that is not vulnerable or flawed.
charles
Perhaps an over generalization, yes it is. I did forget about our important software backing (ie linux in general). What i should of said is phpBB is VERY popular and in HEAVY usage that it gets exploited.
vBulletin® v3.7.3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.