vendor:
6kbbs
by:
insight-labs
N/A
CVSS
MEDIUM
Cross-site request forgery, Information Leakage, Cross Site Scripting
CWE
Product Name: 6kbbs
Affected Version From: 6KBBS v8.0 build 20101201
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2011
6kbbs Multiple Vulnerabilities
1. Cross-site request forgery (getshell) - vulnerable file: /admin/user_ajax.php2. Cross-site request forgery (getshell) - vulnerable file: /admin/portalchannel_ajax.php3. Information Leakage - vulnerable file: /admin/portalcollect.php /getfiles.php?f=http://xxx&t=js4. Cross Site Scripting Vulnerabilities - many files directly use $_SERVER['PHP_SELF'] and not sanitize causing XSS Vulnerabilities
Mitigation:
1. Implement proper CSRF protection mechanisms such as using anti-CSRF tokens and verifying the Referer header.2. Sanitize user input and file names to prevent unauthorized file creation or execution.3. Limit access to sensitive files and directories.4. Implement input sanitization to prevent XSS vulnerabilities.