7.5
CVSSv2

CVE-2005-0614

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

sessions.php in phpBB 2.0.12 and previous versions allows remote malicious users to gain administrator privileges via the autologinid value in a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 1.0.0

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0_beta1

phpbb group phpbb 2.0_rc1

phpbb group phpbb 1.2.0

phpbb group phpbb 1.2.1

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0_rc2

phpbb group phpbb 2.0_rc3

phpbb group phpbb 2.0_rc4

phpbb group phpbb 1.4.0

phpbb group phpbb 1.4.1

phpbb group phpbb 1.4.2

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 1.4.4

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.9

Exploits

#!/usr/bin/perl -w # phpBB <=2012 session autologin exploit # This script uses the vulerability in autologinid variable # More: wwwphpbbcom/phpBB/viewtopicphp?f=14&t=267563 # # Just gives an user on vulnerable forum administrator rights # You should register the user before using this ;-) # by Kutas, kutas@mail15com #PS ...
phpBB 2012 Session Handling Authentication Bypass easy to use exploit ** YOU DON'T HAVE TO REGISTER AT THE VICTIM'S FORUM 1- Simply VISIT the forum using Mozilla Firefox and be sure that the cookie is made (: 3- Close the Browser 2- Open the cookiestxt ((located on "C:\Documents and Settings\ALI\Application Data\Mozilla\ ...
/* Paisterist's code was nice but heres mil's version * precompiled: githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/897rar * Usage: * bcc32 897cpp * and place the exe in your firefox profile dir * Usually C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\somethingdefault * Visit a si ...