vendor:
phpBB
by:
SECU
5.5
CVSS
MEDIUM
Web Worm
79
CWE
Product Name: phpBB
Affected Version From: phpBB version 2.0.10 and earlier
Affected Version To: phpBB version 2.0.10
Patch Exists: YES
Related CWE:
CPE: a:phpbb:phpbb:2.0.10
Platforms Tested:
2004
Santy.A – phpBB <= 2.0.10 Web Worm Source Code (Proof of Concept)
Santy.A is a web worm that targets phpBB version 2.0.10 and earlier. It spreads by exploiting a vulnerability in the software and uses Google to search for vulnerable phpBB installations. Once found, the worm attempts to infect the vulnerable site by injecting malicious code. The worm was first discovered in 2004 and is considered a proof of concept.
Mitigation:
Update to a patched version of phpBB (2.0.11 or later) to prevent infection. It is also recommended to regularly update and patch any web applications to protect against known vulnerabilities.