Gender Mod Exploit!?

Mod that adds a extra field to the users profile, the gender is displayed beside the posts

Moderator: Moderators

Forum rules
The content in this forum is dated Dec. 21 2005 and can be used as Archive only. This Forum is LOCKED and READ ONLY !

Gender Mod Exploit!?

Postby gurlzlubme on Tue 22. Feb, 2005 10:28

Is this true with the latest version of gender mod?

I found this post recently...

A vulnerability was reported in the phpBB bulletin board software. When used with the 'Gender Mod' modification, a remote authenticated user can gain administrative privileges on the forum.

It is reported that Gender Mod contains an input validation flaw that allows remote authenticated users to inject SQL fields into the UPDATE sql command. A remote user can assign the value 'user_level = 1' to gain administrator privileges on the bulletin board.

The following demonstration exploit steps are provided:

1. Save the User Profile page into your disk to modify it offline.

2. Add the correct full post action address (http://forum.victim.com/...):
<FORM action=http://forum.victim.com/profile.php?sid=<current_session_id> method=post encType=multipart/form-data>

3. Modify the HTML Form so that the input field "gender" has value like:
<input type=text name=gender value="0, user_level = 1 ">

4. Load this page in the same browser window where the cookie is still available.

Then, hit 'Submit' to change the user profile.

The vendor has reportedly been notified.


http://www.phpadvisory.com/advisories/view.phtml?ID=52


Edit: nevermind. I see that the latest version fixes this.
gurlzlubme
Poster
Poster
 
Posts: 29
Joined: Wed 03. Nov, 2004 07:10

Postby kooky on Sat 26. Feb, 2005 20:24

Yes it's an old issue, fixed in latest versions :wink:
kooky
brilliant supporter
 
Posts: 1329
Joined: Tue 31. Dec, 2002 17:52
Location: Au pays des rêves


Return to Gender [2.0.10/EM]

Who is online

Users browsing this forum: No registered users and 1 guest

cron