BlackBoard Internet Newsboard System checkdb.inc.php libpath Parameter Remote File Inclusion

high Nessus Plugin ID 15450

Synopsis

Arbritrary code may be run on the remote host.

Description

The remote host is running the BlackBoard Internet Newsboard System, an open source, PHP-based internet bulletin board software application.

The remote version of this software is vulnerable to a remote file include flaw in checkdb.inc.php, due to a lack of sanitization of user-supplied data to the 'libpath' parameter.

Successful exploitation of this issue may allow an attacker to execute malicious script code on a vulnerable server.

*** Nessus reports this vulnerability using only
*** information that was gathered. Therefore,
*** this might be a false positive.

Solution

Upgrade to the newest version of this software.

Plugin Details

Severity: High

ID: 15450

File Name: blackboard_remote_file_include.nasl

Version: 1.20

Type: remote

Family: CGI abuses

Published: 10/11/2004

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.3

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:blackboard_internet_newsboard_system:blackboard_internet_newsboard_system

Required KB Items: www/PHP

Exploit Available: true

Exploit Ease: No exploit is required

Vulnerability Publication Date: 10/6/2004

Reference Information

CVE: CVE-2004-1582

BID: 11336