Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SCAN:MISC:HTTP:VIOLATION-ACCS

Severity

Info

Recommended

No

Category

SCAN

Keywords

PHP

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SCAN: Phorum Violation Access


This signature detects attempts to access the vulnerable violation.php3 script in Phorum, a free, open source forum/discussion package for Web sites. Attackers can send maliciously crafted URL requests to violation.php3 to arbitrarily relay e-mail through the host MTA.

Extended Description

Phorum is a freely available, open source package originally written by Brian Moon. The package is designed to add enhanced features to a web page, allowing users to interact through bulletin board style chats forums and discussions. A problem with the Phorum package could allow remote users to arbitrarily relay email. Due to the way violation.php3 handles URL's as arguments, it is possible to create a custom crafted URL request to the script which will allow a remote user to send email through the hosts MTA. This email will then be delivered to the specified person with the appearance of coming from the web host. This problem makes it possible for a user with malicious intentions to socially engineer, mailbomb, or spam from the web host, and potentially get the host blacklisted in one of such lists.

Affected Products

  • Brian Moon Phorum 3.0.7

References

  • BugTraq: 2272
  • URL: http://www.cgisecurity.com/archive/php/phorum.txt

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out