Vulnerabilities > CVE-2005-2651 - Unspecified vulnerability in PHPoutsourcing Zorum 3.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpoutsourcing
nessus
Summary
gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | ZORUM_MULTIPLE_VULNS.NASL |
description | The remote host is running Zorum, an open source electronic forum written in PHP. The version of Zorum installed on the remote host is prone to numerous flaws, including remote code execution, privilege escalation, and SQL injection. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17312 |
published | 2005-03-11 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17312 |
title | Zorum <= 3.5 Multiple Remote Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/107510/familyconnections-exec.txt |
id | PACKETSTORM:107510 |
last seen | 2016-12-05 |
published | 2011-12-04 |
reporter | mr_me |
source | https://packetstormsecurity.com/files/107510/Family-Connections-CMS-2.7.1-Remote-Command-Execution.html |
title | Family Connections CMS 2.7.1 Remote Command Execution |
Seebug
bulletinFamily exploit description No description provided by source. id SSV:72389 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-72389 title Family Connections CMS 2.5.0 & 2.7.1 - (less.php) Remote Command Execution bulletinFamily exploit description BugCVE: CVE-2005-2651 BUGTRAQ: 14601 Zorum的/gorum/prod.php文件中存在远程代码执行漏洞: 07 $doubleApp = isset($argv[1]); ... 14 if( $doubleApp ) 15 { 16 $appDir = $argv[1]; 17 system("mkdir $prodDir/$appDir"); ... Zorum 3.5 厂商补丁: Zorum ----- 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: http://zorum.phpoutsourcing.com/ id SSV:12215 last seen 2017-11-19 modified 2009-09-05 published 2009-09-05 reporter Root source https://www.seebug.org/vuldb/ssvid-12215 title Zorum 3.5 /gorum/prod.php 远程代码执行漏洞
References
- http://marc.info/?l=bugtraq&m=112438781604862&w=2
- http://marc.info/?l=bugtraq&m=112438781604862&w=2
- http://rgod.altervista.org/zorum.html
- http://rgod.altervista.org/zorum.html
- http://secunia.com/advisories/16504/
- http://secunia.com/advisories/16504/
- http://securitytracker.com/id?1014725
- http://securitytracker.com/id?1014725
- http://www.securityfocus.com/bid/14601
- http://www.securityfocus.com/bid/14601
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21912
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21912