-----BEGIN PGP SIGNED MESSAGE----- Hash: RIPEMD160 --------------------------------------------------- | BuHa Security-Advisory #2 | Sep 17th, 2005 | | feat. SePro Bugtraq | | --------------------------------------------------- | Vendor | vBulletin | | URL | http://vbulletin.com/ | | Version | <= vBulletin 3.0.7 | | Risk | Moderate (SQL-Injection and | | | Arbitrary File Upload) | --------------------------------------------------- The vBulletin team released version 3.0.8 of their software at the same time as we dropped them a mail about several security related issues. They already had addressed a couple of problems we mentioned in our mail but they did not fix all named security issues so we decided to release two advisories - one for the version 3.0.8 and the other one for the latest version 3.0.9. Unfortunately the vBulletin team did not consider it necessary to release *any* information about security problems in their software to the public not to mention send us details about the bugs they fixed therefore we have to determine the differences between the versions on our own. o Description: ============= vBulletin is a powerful, scalable and fully customizable forums package for your web site. It has been written using the Web's quickest-growing scripting language; PHP, and is complemented with a highly efficient and ultra fast back-end database engine built using MySQL. [...] Visit http://vbulletin.com/ for detailed information. o SQL-Injection: =============== > /joinrequests.php: POST: A moderator is able to read sensitive data like Private Messages, Password Hashes etc. > /modcp/announcement.php: POST: > /modcp/thread.php: POST: POST: > /modcp/user.php: GET: There are a lot of security related bugs in the administrator panel of the vBulletin software. An authorized user could elevate his privileges and read sensitive data. > /admincp/admincalendar.php: GET: GET: GET: GET: POST: GET: POST: POST: GET: POST: POST: POST: GET: POST: POST: POST: > /admincp/cronlog.php: POST: POST: > /admincp/email.php: POST: > /admincp/help.php: POST: > /admincp/user.php: GET: GET: > /admincp/usertitle.php: GET: GET: > /admincp/language.php: POST: > /admincp/phrase.php: POST: > /admincp/template.php: GET: GET: POST: > /admincp/thread.php:: POST: > /admincp/usertools.php: POST: Not included in standard vBulletin release: > /admincp/vbugs_admin.php: GET: GET: GET: o Arbitrary File Upload: ======================= Any user with access to administrator panel (e.g. (Co)Administrator) and the privilege to add avatars/icons/smileys is able to upload arbitrary files. An attacker is able to gain the ability to execute commands under the context of the web server. > /admincp/image.php: POST: POST: POST: o XSS: ===== > /modcp/index.php: GET: > /modcp/user.php: GET: > /admincp/css.php: GET: > /admincp/index.php: GET: GET: > /admincp/user.php: GET: > /admincp/usertitle.php: GET: > /admincp/language.php: GET: > /admincp/modlog.php: GET: > /admincp/template.php: GET: GET: GET: Not included in standard vBulletin release: > /admincp/vbugs_admin.php: GET: Even a privileged user should not be able to add posts, titles, announcements etc. with HTML/JavaScript-Code in it. > Not properly filtered: (XSS) o Disclosure Timeline: ===================== 20 Jul 05 - Security flaws discovered. 29 Jul 05 - Vendor contacted. 29 Jul 05 - Vendor released 'bugfixed' version. 17 Sep 05 - Public release. o Solution: ========== Upgrade to vBulletin 3.0.9 [1] o Credits: ========= deluxe Security-Project - http://security-project.org/projects/board/ - - --- Thomas Waldegger BuHa-Security Community - http://buha.info/board/ If you have questions, suggestions or criticism about the advisory feel free to send me a mail. The address 'bugtraq@morph3us.org' is more a spam address than a regular mail address therefore it's possible that I ignore some mails. Please use the contact details at http://morph3us.org/ to contact me. Greets fly out to cyrus-tc, destructor, nait, rhy (you Pongo-Pongo king, eh!1! :oP), trappy and all members of BuHa. Advisory online: http://morph3us.org/advisories/20050917-vbulletin-3.0.7.txt [1] http://www.vbulletin.com/forum/showthread.php?p=961409 -----BEGIN PGP SIGNATURE----- Version: n/a Comment: http://morph3us.org/ iD8DBQFD9YF1kCo6/ctnOpYRA1PBAJsHGa6U0d2P5F9G6RDEp5M79An+IQCgnwSN 9Bp3RVHR6nGd6vsx4WmdweM= =9ZRW -----END PGP SIGNATURE-----