phpBB < 2.0.9 Multiple Vulnerabilities

high Nessus Plugin ID 13655

Synopsis

A remote web application is vulnerable to SQL injection.

Description

The remote host is running a version of phpBB older than 2.0.9.

There is a flaw in the remote software that may allow anyone to inject arbitrary SQL commands, which may in turn be used to gain administrative access on the remote host or to obtain the MD5 hash of the password of any user.

One vulnerability is reported to exist in 'admin_board.php'. The other pertains to improper characters in the session id variable.

Solution

Upgrade to 2.0.9

Plugin Details

Severity: High

ID: 13655

File Name: phpbb_sql_injection3.nasl

Version: 1.22

Type: remote

Family: CGI abuses

Published: 7/21/2004

Updated: 6/4/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:phpbb_group:phpbb

Required KB Items: www/phpBB

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: No exploit is required

Vulnerability Publication Date: 7/13/2004

Reference Information

BID: 10722