PT-2008-3393 · Exbb · Exbb Italia

The:Paradox

·

Publicado

2008-04-17

·

Atualizado

2017-09-29

·

CVE-2008-1862

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ExBB Italia versions 0.22 and earlier
Description The issue allows remote attackers to bypass a check by using vectors other than GET requests with QUERY STRING, specifically via (1) POST or (2) COOKIE variables. This can be leveraged to conduct PHP remote file inclusion attacks by manipulating the new exbb[home path] or exbb[home path] parameter in the "modules/threadstop/threadstop.php" endpoint.
Recommendations For ExBB Italia versions 0.22 and earlier, as a temporary workaround, consider restricting access to the modules/threadstop/threadstop.php endpoint to minimize the risk of exploitation. Avoid using the new exbb[home path] and exbb[home path] parameters in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1862

Produtos afetados

Exbb Italia