|
Family: CGI abuses --> Category: infos
vBulletin Misc.PHP PHP Script Code Execution Vulnerability Vulnerability Scan
Vulnerability Scan Summary Executes phpinfo() on the remote host
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that allows execution of
arbitrary PHP code.
Description :
The remote version of vBulletin fails to sanitize input to the
'template' parameter of the 'misc.php' script. Provided the 'Add
Template Name in HTML Comments' setting in vBulletin is enabled, an
unauthenticated attacker may use this flaw to execute arbitrary PHP
commands on the remote host.
See also :
http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0468.html
Solution :
Upgrade to vBulletin 3.0.7 or later.
Threat Level:
Medium / CVSS Base Score : 6
(AV:R/AC:H/Au:NR/C:P/A:P/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|