vendor:
My Simple Forum
by:
Giovanni Buzzin, Osirys
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: My Simple Forum
Affected Version From: My Simple Forum v7.1
Affected Version To: My Simple Forum v7.1
Patch Exists: No
Related CWE:
CPE:
Platforms Tested:
My Simple Forum v7.1 Remote Command Execution Exploit
This exploit allows an attacker to execute commands remotely on a server running My Simple Forum v7.1. The vulnerability is caused by a local file inclusion vulnerability at /theme/default/index.template.php?action=[lf]%00. Additionally, there is an XSS vulnerability at /theme/default/index.template.php?Name=[XSS] which requires Register Globals to be turned on. The exploit was discovered by Giovanni Buzzin and Osirys.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of My Simple Forum or apply any security patches provided by the vendor.