Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

PhpBB admin pannel vulnerability


ghost's Avatar
0 0

Let's assume I get access to admin pannel Is it possible to upload a file to server (or insert exploit -> php code) in any part of forum or admin pannel. Hope I was clear enought. Tnx


Mr_Cheese's Avatar
0 1

write a php upload script, then upload webadmin.

easy!


ghost's Avatar
0 0

Well when you login as admin go to the general admin -> configuration -> Allowed HTML tags and there for instance put in script or so, you know what to input ;) then you can use those html tags in each forum post you make.

For the inputting of source maybe this way


ghost's Avatar
0 0

I have still problems with it, there is no problem to write php upload script, but how can I get it to work. In configuration I can write html code, but what about php? Or is there any other option to include my upload script (with html, javascript)?


Mr_Cheese's Avatar
0 1

we are also having the same problems.

Anarchio-Hippie and i are using the [script language="php"] to get php onto a page. However, the forum doesnt seem to like php.

We are still working on a way round this, so if we find anything, we will post it.


ghost's Avatar
0 0

I read your reply on the post i made but i think i explained wrong. the allow html commands box contains all the commands that are accepted so that you can post in a post in the forums, so by adding script to that line you can post script language in a post. So for instance make a cookie stealer etc

Hope i explained it a little better now ;)

  • make sure to put the html code on, also something you do in the configuration menu

ghost's Avatar
0 0

I know there is no problem to use this form for html or javascript. But I don't find any option to use php (or probably any server side languages). So if I have acess to adimin pannel, there is still no option to get acess to files on server. If somebody find the option it would be great.


ghost's Avatar
0 0

I think you would have to use webadmin and then write it in yourself. sort of like what you did with the team cheese site during webwars! ;)


ghost's Avatar
0 0

Omni there is no problem to write an upload script (or webadmin if you like it). Problem is to put it to server, so you can use it.


ghost's Avatar
0 0

does anyone know where to find a version of webadmin thay actually works?


ghost's Avatar
0 0

..well, get to an phpBB panel and read!! Not to hard.