J-Security Center

Title: PHPOutsourcing Zorum Remote Include Command Execution Vulnerability

Severity: HIGH

Description:

Zorum is a freely available, open source PHP forum. It is available for UNIX, Linux, and Microsoft operating systems.

A problem could make it possible for remote users to execute arbitrary commands.

It has been reported that Zorum may allow remote users to influence to location of PHP includes. Because of this, it is possible for a remote user to include an external arbitrary PHP script containing commands that may be carried out on the vulnerable host.

This problem could allow a remote attacker to execute arbitrary code with the privileges of the web server process. This could result the attacker gaining local access, and potentially elevated privileges.

Affected Products:

  • PHPOutsourcing Zorum 3.0.0
  • PHPOutsourcing Zorum 3.1.0
  • PHPOutsourcing Zorum 3.2.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.