20010515 DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2)mailing list
http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html CVE-2001-0527
DCForum 6.0 - Remote Admin Privilege Arbitrary Commands
Record summary
CVE-2001-0527 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDCForum 6.0 - Remote Admin Privilege Arbitrary CommandsExploitDB exploitby Franklin DeMattoNot analyzed1 file
References
6dcscripts.comConfirmation
http://www.dcscripts.com/dcforum/dcfNews/167.html 480vdb entry
http://www.osvdb.org/480 2728vdb entry
http://www.securityfocus.com/bid/2728 dcforum-cgi-admin-access(6538)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6538 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0527