OSVDB ID: 25005

Title: Invision Power Board search.php lastdate Variable Arbitrary PHP Code Execution

Info

Disclosure

Apr 25, 2006

Discovery

Unknown

Dates

Exploit

Apr 25, 2006

Solution

Unknown

Description

Invision Power Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not properly validate the 'lastdate' variable in a "preg_replace()" call in the search.php script. This could allow a user to inject and execute arbitrary PHP code via the "e" pattern modifier, leading to a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.

Products

Invision Power Services, Inc.

Invision Power Board

2.1.5 (2006.03.08)
2.1.5 (2006.04.25)
2.0.x
2.1
2.1 Alpha2
2.1.2
2.1.3
2.1.4

References

Credit

  • IceShaman - http://HackThisSite.org
  • Wells - http://HackThisSite.org


Direct URL: http://osvdb.org/25005