Vulnerabilities > CVE-2005-4135 - Remote Arbitrary Command Execution vulnerability in Simplebbs 1.0.6/1.0.7/1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
simplemedia
nessus
exploit available

Summary

Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.

Vulnerable Configurations

Part Description Count
Application
Simplemedia
3

Exploit-Db

descriptionSimpleBBS <= 1.1 Remote Commands Execution Exploit (c code). CVE-2005-4135. Webapps exploit for php platform
idEDB-ID:1361
last seen2016-01-31
modified2005-12-07
published2005-12-07
reporterunitedasia
sourcehttps://www.exploit-db.com/download/1361/
titleSimpleBBS <= 1.1 - Remote Commands Execution Exploit c code

Nessus

NASL familyCGI abuses
NASL idSIMPLEBBS_NAME_CMD_EXEC.NASL
descriptionThe remote host appears to be running SimpleBBS, an open source bulletin board system written in PHP. The version of SimpleBBS installed on the remote host fails to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id20303
published2005-12-14
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/20303
titleSimpleBBS topics.php name Parameter Arbitrary Command Execution