Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


vBulletin, phpBB, & IPB Skins vBulletin Skins

Register
Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,638 Members
164,117 Posts
50 Users Online

Please welcome our newest member, com2kltds!

Affiliates
Go Back AdminFusion » Getting Started » Software » forum software security & vulnerabilities
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 06-25-2008, 07:42 PM   #1

Title: Lurker

Points: 14, Level: 1Points: 14, Level: 1Points: 14, Level: 1
Level up: 1%, 36 Points neededLevel up: 1%, 36 Points neededLevel up: 1%, 36 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jun 2008

Posts: 1

Nolagurl is on a distinguished road
 
 
Question forum software security & vulnerabilities

Hi all,

Can anyone help me make sense of this...

I was researching forum softwares, and came across this website:
National Vulnerability Database

Does anyone know what all this stuff below means, are these things that I should be concerned about? Almost every forum software is listed with numerous issues. Below are a few examples and just the first entry listed under each software.

I'm new to all this, so my apologies if this was previously explored.

Also, does anyone know which software is "known" to be the most secure....which is the absolute worst?

Any information is greatly appreciated.

Mardi Gras Hugs to all!



VBulletin
1st entry:
Overview

SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.


References to Advisories, Solutions, and Tools

External Source: XF (disclaimer)

Name: cauposhopclassic-saarticleid-sql-injection(43200)

Hyperlink: ISS X-Force Database: cauposhopclassic-saarticleid-sql-injection(43200): CaupoShop Classic saArticle[ID] SQL injection


PHPbb
Original release date: 5/28/2008
Last revised: 5/28/2008
Source: US-CERT/NIST


Overview

PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.


Impact

CVSS Severity (version 2.0):
CVSS v2 Base score: 10.0 (High) (AV:N/AC:L/Au:N/C:C/I:C/A:C) (legend)
Impact Subscore: 10.0
Exploitability Subscore: 10.0

Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: Provides administrator access, Allows complete confidentiality, integrity, and availability violation , Allows unauthorized disclosure of information , Allows disruption of service



IPB
Original release date: 3/17/2008
Last revised: 3/18/2008
Source: US-CERT/NIST


Overview

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 before 2008-03-13 allows remote attackers to inject arbitrary web script or HTML via nested BBCodes, a different vector than CVE-2008-0913.


Impact

CVSS Severity (version 2.0):
CVSS v2 Base score: 4.3 (Medium) (AV:N/AC:M/Au:N/C:N/I/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6

Access Vector: Network exploitable , Victim must voluntarily interact with attack mechanism
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type: Allows unauthorized modification
Reply With Quote
Old 06-28-2008, 07:16 PM   #2

Oldiesmann's Avatar

Title: Member

Points: 1,871, Level: 12Points: 1,871, Level: 12Points: 1,871, Level: 12
Level up: 13%, 279 Points neededLevel up: 13%, 279 Points neededLevel up: 13%, 279 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Apr 2006

Posts: 70

Location: Cincinnati, Ohio

Oldiesmann is on a distinguished road
Send a message via AIM to Oldiesmann Send a message via MSN to Oldiesmann Send a message via Yahoo to Oldiesmann  
 
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Unwritten Rules of Forums Ryan Handling Problem Members 3 08-17-2008 02:17 AM
Top ten ways to make your forum community stand out. CompletevB Planning and Brainstorming 16 08-13-2007 02:02 AM
Why most forums fail within first year of their existence bcmtouring Forums General 13 05-14-2007 06:40 PM
Starting a new forum, which software? rockinaway Software 16 11-01-2006 09:01 PM
Introduction to Forum Promotion htmlmaster Creating Interest 3 06-12-2006 04:53 PM

AdminFusion

All times are GMT +1. The time now is 01:51 PM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72