Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-1315
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1315

Description:
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/18052

SAID
  Secunia Advisory: SA13239

GENTOO
  http://marc.theaimsgroup.com/?l=bugtraq&m=110143995118428&w=2

CONFIRM
  http://www.phpbb.com/phpBB/viewtopic.php?t=240513

CERT-VN
  497400

CERT
  http://www.us-cert.gov/cas/techalerts/TA04-356A.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/385208
  http://marc.theaimsgroup.com/?l=bugtraq&m=110365752909029&w=2
  http://marc.theaimsgroup.com/?t=110079440800004&r=1&w=2
  http://marc.theaimsgroup.com/?l=bugtraq&m=110029415208724&w=2

BID
  10701


Return to the previous page.