Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200503-02] phpBB: Multiple vulnerabilities Vulnerability Scan


Vulnerability Scan Summary
phpBB: Multiple vulnerabilities

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200503-02
(phpBB: Multiple vulnerabilities)


It was discovered that phpBB contains a flaw in the session
handling code and a path disclosure bug. AnthraX101 discovered that
phpBB allows local users to read arbitrary files, if the "Enable remote
avatars" and "Enable avatar uploading" options are set (CVE-2005-0259).
He also found out that incorrect input validation in
"usercp_avatar.php" and "usercp_register.php" makes phpBB vulnerable to
directory traversal attacks, if the "Gallery avatars" setting is
enabled (CVE-2005-0258).

Impact

Remote attackers can exploit the session handling flaw to gain
phpBB administrator rights. By providing a local and a remote location
for an avatar and setting the "Upload Avatar from a URL:" field to
point to the target file, a malicious local user can read arbitrary
local files. By inserting "/../" sequences into the "avatarselect"
parameter, a remote attacker can exploit the directory traversal
vulnerability to delete arbitrary files. A flaw in the "viewtopic.php"
script can be exploited to expose the full path of PHP scripts.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0258
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0259
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=267563


Solution:
All phpBB users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/phpBB-2.0.13"


Threat Level: Medium


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.