vendor:
phpBB
by:
evilrabbi
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: phpBB
Affected Version From: 1.0.0
Affected Version To: 2.0.10
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Exploit for phpBB 1.0.0 – 2.0.10
This exploit allows an attacker to execute arbitrary commands on a system running phpBB versions 1.0.0 to 2.0.10. The attacker needs to modify the b4b0.php file with the correct URL to their backdoor and the correct filename for the backdoor. After uploading the modified file to a web server, the attacker can use telnet to connect to the exploited system and execute commands.
Mitigation:
Upgrade phpBB to a version that is not vulnerable to this exploit.