Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 88503

Summary: www-apps/phpbb: File Upload Script 'up.php' Lets Remote Users Upload Arbitrary Files
Product: Gentoo Security Reporter: Jean-François Brunette (RETIRED) <formula7>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: normal    
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://securitytracker.com/alerts/2005/Apr/1013671.html
Whiteboard:
Package list:
Runtime testing required: ---

Description Jean-François Brunette (RETIRED) gentoo-dev 2005-04-09 12:39:30 UTC
Don't know if it applies...
---------------------------------------
Version(s): 1.1

Description:  A vulnerability was reported in the 'File Upload Script' phpBB MOD. A remote user can upload files with arbitrary content and filename extensions.

The 'up.php' script does not restrict filename extensions or file contents. A remote user can upload an arbitrary file with a '.php' file extension. Then, the remote user can invoke the uploaded file to execute arbitrary PHP code and operating system commands on the target system with the privileges of the target web service.

Impact:  A remote user can upload arbitrary PHP code to the target system and then execute the code with the privileges of the target web service.

Solution:  No solution was available at the time of this entry.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-04-10 07:47:10 UTC
This mod is not in the phpBB shipped in portage.