Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

phpBB Multiple Input Validation Vulnerabilities

The following proof of concept has been provided:
admin_smilies.php?mode=edit&id=[SQL]
admin_smilies.php?mode=delete&id=[SQL]
admin_smilies.php?mode=edit&id=[XSS]
admin_smilies.php?mode=delete&id=[XSS]
admin_styles.php?mode=edit&style_id=[SQL]
admin_styles.php?mode=delete&style_id=[SQL]
admin_styles.php?mode=edit&style_id=[XSS]
admin_styles.php?mode=delete&style_id=[XSS]

Further proof of concept can be obtained from the following location:
http://www.gulftech.org/vuln/phpBBpoc/







 

Privacy Statement
Copyright 2009, SecurityFocus