Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Powerboards User Account Arbitrary File Creation Vulnerability

Powerboards is a bulletin board application developed in PHP.

An issue has been reported in Powerboards, which allows a user to create files and retrieve those created files.

Reportedly, when a user signs up to the service a file is created with the chosen username as the filename. The file contains user information and can be disclosed to remote users via a web request. Requesting a file of any known user will disclose sensitive user information.

This issue can potentially be used to execute arbitrary code on the host. If a user creates an account containing malicious content, upon the user submitting a web request to retrieve the known file, the malicious content could execute.







 

Privacy Statement
Copyright 2009, SecurityFocus