Secunia Security Advisory - Terencentanio Enache has reported a vulnerability in MyPHP Forum, which can be exploited by malicious users to conduct spoofing attacks.
dd98c579eb94d80dffb8971d674bf4cf9b20a2e906ebbeff0e5a2760a7bf2e38
----------------------------------------------------------------------
Want a new IT Security job?
Vacant positions at Secunia:
http://secunia.com/secunia_vacancies/
----------------------------------------------------------------------
TITLE:
MyPHP Forum Sender Spoofing Vulnerability
SECUNIA ADVISORY ID:
SA15166
VERIFY ADVISORY:
http://secunia.com/advisories/15166/
CRITICAL:
Less critical
IMPACT:
Spoofing
WHERE:
>From remote
SOFTWARE:
MyPHP Forum 3.x
http://secunia.com/product/5005/
MyPHP Forum 2.x
http://secunia.com/product/5006/
MyPHP Forum 1.x
http://secunia.com/product/4631/
DESCRIPTION:
Terencentanio Enache has reported a vulnerability in MyPHP Forum,
which can be exploited by malicious users to conduct spoofing
attacks.
The problem is that the identity of a message sender is taken from
user supplied input. This can be exploited to spoof the username by
modifying the "nbuser" / "sender" parameter in a POST request to
"post.php" / "privmsg.php".
The vulnerability has been reported in version 3. Version 1 and 2 may
reportedly also be affected.
SOLUTION:
Edit the source code to ensure that the identity of senders are
properly verified.
PROVIDED AND/OR DISCOVERED BY:
Terencentanio Enache
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------