what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mayhemic Labs Security Advisory 2006.4

Mayhemic Labs Security Advisory 2006.4
Posted Nov 29, 2006
Authored by Mayhemic Labs Security, Mayhemic Labs | Site mayhemiclabs.com

Mayhemic Labs Public Advisory MHL-2006-004 - MBoard does not check the Post ID for malicious data when replying, allowing an attacker to create blank files on the system wherever the web server has write access. Versions 1.22 and below are affected.

tags | advisory, web
SHA-256 | dc3792e64bd8c279e0c5bc8ef1dbd4d1d6abe41cce79d600cbf424d8b5ea242f

Mayhemic Labs Security Advisory 2006.4

Change Mirror Download
MHL-2006-004 - Public Advisory

+-----------------------------------------------------------+
| mboard Security Issue |
+-----------------------------------------------------------+


PUBLISHED ON
November 26th, 2006


PUBLISHED AT
http://www.mayhemiclabs.com/advisories/MHL-2006-004.txt
http://www.mayhemiclabs.com/wiki/wikka.php?wakka=MHL2006004


PUBLISHED BY
Mayhemic Labs
http://www.mayhemiclabs.com

security AT mayhemiclabs DOT com
GPG key: 0x56143F84


APPLICATION
MBoard - PHP message board
http://www.phpjunkyard.com/php-message-board.php

"MBoard is a PHP message board script (a simple forum)."


AFFECTED VERSIONS
Versions 1.22 and below


ISSUES
MBoard does not check the Post ID for malicious data when replying,
allowing an attacker to create blank files on the system wherever
the web server has write access.

Example: An attacker can reply to a message, and edit the "orig_id"
variable to something malicious ("../../../../../../tmp/ZOMGHAX")
mboard will then create the specified file (appending the
configured extension.

WORKAROUNDS
Enabling Magic Quotes will negate the issue.


SOLUTIONS
Upgrade to version 1.3


REFERENCES
MBoard - http://www.phpjunkyard.com/php-message-board.php


TIMELINE
October 11th, 2006
Vendor/Developer Notified
Vendor/Developer Response Recieved

October 25th, 2006
Vendor/Developer Followup
Vendor/Developer Response Recieved

November 16th, 2006
Vendor/Developer Followup

November 18th, 2006
New Version Released

November 26th, 2006
Advisory Released


ADDITIONAL CREDIT
N/A

LICENSE
Creative Commons Attribution-ShareAlike License
http://creativecommons.org/licenses/by-sa/2.5

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close