|
Powerboards User Account Arbitrary File Creation Vulnerability
Powerboards is a bulletin board application developed in PHP. An issue has been reported in Powerboards, which allows a user to create files and retrieve those created files. Reportedly, when a user signs up to the service a file is created with the chosen username as the filename. The file contains user information and can be disclosed to remote users via a web request. Requesting a file of any known user will disclose sensitive user information. This issue can potentially be used to execute arbitrary code on the host. If a user creates an account containing malicious content, upon the user submitting a web request to retrieve the known file, the malicious content could execute. |
|
|
Privacy Statement |