This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

phpBB Vuln - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Be on the Lookout for PHP compromises
- http://isc.sans.org/diary.php?date=2005-07-01
Updated July 1st 2005 22:37 UTC
"This is a call to all the network and system security folks out there… Please be on the lookout for web-based intrusions happening in your environments. There have recently been major vulnerabilities discovered in phpBB and the XML_RPC libraries*, which we have reported in the last two days. It's very likely that these vulnerabilities will be utilized to compromise systems. Try to be vigilant about securing your environment and reviewing your IDS alerts for attacks…"

* http://isc.sans.org/diary.php?date=2005-06-30
"XMLRPC Vulnerabilities (fixed)
…discovered in XMLRPC libraries for PHP:
PHPXMLRPC
Version 1.1 is vulnerable to remote code execution via a careless eval call. The hole has been fixed and a patch is available.
PEAR XML_RPC Library
Versions 1.3.0 and earlier are vulnerable to remote code execution. The issue has been fixed and a patch is available.
These libraries are found in a number of applications such as postnuke, drupal, TikiWiki, and b2evolution.
Advisory Info:
http://www.securityfocus.com/bid/14088
http://www.securityfocus.com/bid/14094
http://www.frsirt.com/english/advisories/2005/0911
http://www.frsirt.com/english/advisories/2005/0912 …"

:ph34r: