SimpleBBS v.1.1 name PHP Code Injection Security Vulnerability
Description
Input passed to the "name" parameter when adding a new topic isn't properly sanitised before being stored in a PHP script. This can be exploited to inject and execute arbitrary PHP code in to "/data/post.php" file.
Confirmed in version 1.1. Other versions may also be affected.
Impact
This issue may allow a remote attacker to execute arbitrary commands in the context of the web server that is hosting the vulnerable software.
References
Secunia SA17949
Product Homepage
View entire list of over 400 known Web Application Vulnerabilities and the specific technologies which they target. See Web Vulnerabilities in popular applications such as: WordPress, Tiki Wiki, PHPNuke, PHPMyAdmin, phpBB, Mambo, PHP-Fusion, Mantis, Invision Power Board
Get latest new web vulnerabilities via RSS 
|