PT-2005-4834 · Simplebbs · Simplebbs

Published

2005-12-09

·

Updated

2018-10-19

·

CVE-2005-4135

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SimpleBBS versions 1.1 and earlier
Description A direct static code injection issue allows remote attackers to execute arbitrary commands. This is achieved by injecting shell metacharacters in the Host header, possibly through the name parameter or variable, which is then written to data/topics.php.
Recommendations For SimpleBBS versions 1.1 and earlier, consider restricting access to the includes/newtopic.php file until a patch is available. As a temporary workaround, avoid using the name parameter or variable in the affected API endpoint, and restrict the use of shell metacharacters in the Host header to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4135

Affected Products

Simplebbs