|
|
| |
|
| |
phpBB: multiple vulnerabilities
| Package(s): | phpbb |
CVE #(s): | CAN-2005-0258
CAN-2005-0259
|
| Created: | March 1, 2005 |
Updated: | March 2, 2005 |
| Description: |
It was discovered that phpBB contains a flaw in the session handling
code and a path disclosure bug. AnthraX101 discovered that phpBB allows
local users to read arbitrary files, if the "Enable remote avatars" and
"Enable avatar uploading" options are set (CAN-2005-0259). He also
found out that incorrect input validation in "usercp_avatar.php" and
"usercp_register.php" makes phpBB vulnerable to directory traversal
attacks, if the "Gallery avatars" setting is enabled (CAN-2005-0258). |
| Alerts: |
|
( Log in to post comments)
|
|
|