Synopsis
The remote web server contains a PHP application that suffers from an authentication bypass vulnerability.
Description
The remote host is running YaBB SE, a web-based forum written in PHP.
The version of YaBB SE installed on the remote host allows use of a cookie to bypass authentication. A remote attacker can leverage this issue using a specially crafted value for the cookie to gain access as any user, including the administrator, which could in turn lead to execution of arbitrary commands on the affected host, subject to the privileges under which the web server operates.
Solution
Use another product since YaBB SE is no longer supported.
Plugin Details
File Name: yabbse_cookie_bypass.nasl
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: Exploits are available
Reference Information
BID: 27414