Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1375
    posted: 02/27/09
  • NSM Daily Update #1375
    posted: 02/27/09
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1375
    posted: 02/27/09
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1361
    posted: 02/27/09
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 02/26/09

Title: PHPBB album_portal.php Remote File Include Vulnerability

Severity: HIGH

Description:

phpBB is an open-source web forum application that is written in PHP and supported by a number of database products. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.

A vulnerability has been reported to exist in the software that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system. The issue exists due to improper validation of user-supplied data. The problem exists in the 'phpbb_root_path' parameter of 'album_portal.php' script.

Remote attackers could potentially exploit this issue via a vulnerable variable to include a remote malicious script, which will be executed in the context of the web server hosting the vulnerable software.

Affected Products:

  • phpBB Group phpBB 2.0.0 .0
  • phpBB Group phpBB 2.0.0 Beta 1
  • phpBB Group phpBB 2.0.0 RC1
  • phpBB Group phpBB 2.0.0 RC2
  • phpBB Group phpBB 2.0.0 RC3
  • phpBB Group phpBB 2.0.0 RC4
  • phpBB Group phpBB 2.0.1
  • phpBB Group phpBB 2.0.2
  • phpBB Group phpBB 2.0.3
  • phpBB Group phpBB 2.0.4
  • phpBB Group phpBB 2.0.5
  • phpBB Group phpBB 2.0.6
  • phpBB Group phpBB 2.0.6 c
  • phpBB Group phpBB 2.0.6 d
  • phpBB Group phpBB 2.0.7
  • phpBB Group phpBB 2.0.7 a
  • phpBB Group phpBB 2.0.8
  • phpBB Group phpBB 2.0.8 a

References: