UBB.threads < 6.5.2 beta Multiple Vulnerabilities

high Nessus Plugin ID 18098

Synopsis

The remote web server contains a PHP application that is affected by numerous vulnerabilities.

Description

The remote host is running a version of UBB.threads that suffers from multiple vulnerabilities due to insufficient input validation - local file inclusion, HTTP response splitting, SQL injection, and cross-site scripting. These flaws may allow an attacker to completely compromise the affected installation of UBB.threads.

Solution

Upgrade to UBB.threads 6.5.2 beta or greater.

See Also

https://www.securityfocus.com/archive/1/396222

http://www.gulftech.org/?node=research&article_id=00084-06232005

Plugin Details

Severity: High

ID: 18098

File Name: ubbthreads_printthread_sql_injection.nasl

Version: 1.18

Type: remote

Family: CGI abuses

Published: 4/20/2005

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Required KB Items: www/ubbthreads

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Vulnerability Publication Date: 4/19/2005

Reference Information

CVE: CVE-2005-1199, CVE-2005-2057, CVE-2005-2058, CVE-2005-2059, CVE-2005-2060, CVE-2005-2061

BID: 13253, 14050, 14052, 14053, 14055

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990