[原文]Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.


        PHPOpenChat 3.0.1及更早版本存在多个PHP远程文件包含漏洞,远程攻击者可以通过传给(1)poc_loginform.php或(2)phpbb/poc.php的phpbb_root_path参数,传给(3)phpbb/poc.php,(4)phpnuke/ENGLISH_poc.php,(5)phpnuke/poc.php或(6)yabbse/poc.php的poc_root_path参数,或者传给yabbse/poc.php的sourcedir参数,来执行任意PHP代码。

PHPOpenChat poc_loginform.php phpbb_root_path Parameter Remote File Inclusion
Remote / Network Access Input Manipulation
Loss of Integrity
Exploit Public

- 漏洞描述

PHPOpenChat contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to poc_loginform.php not properly sanitizing user input supplied to the phpbb_root_path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.

- 解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

PHPOpenChat Multiple Remote File Include Vulnerabilities
Input Validation Error 12817
2005-03-15 12:00:00 2006-09-07 09:33:00
Discovery is credited to Albania Security Clan.

- 受影响的程序版本

PHPOpenChat PHPOpenChat 3.0.1
PHPOpenChat PHPOpenChat 2.3.4
PHPOpenChat PHPOpenChat 3.0.2

- 漏洞讨论

PHPOpenChat is prone to multiple remote file-include vulnerabilities.

An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

PHPOpenChat 3.0.1 and prior versions are reported prone to this issue.

- 漏洞利用

An exploit is not required.

The following proof-of-concept examples are available:;w;id;pwd;ps;w;id;pwd;ps;w;id;pwd;ps;w;id;pwd;ps;w;id;pwd;ps

- 解决方案

The vendor has released version 3.0.2 to address these issues. Please see the references for details.

