LWN.net Logo

phpBB: multiple vulnerabilities

Package(s):phpbb CVE #(s):CAN-2005-0258 CAN-2005-0259
Created:March 1, 2005 Updated:March 2, 2005
Description: It was discovered that phpBB contains a flaw in the session handling code and a path disclosure bug. AnthraX101 discovered that phpBB allows local users to read arbitrary files, if the "Enable remote avatars" and "Enable avatar uploading" options are set (CAN-2005-0259). He also found out that incorrect input validation in "usercp_avatar.php" and "usercp_register.php" makes phpBB vulnerable to directory traversal attacks, if the "Gallery avatars" setting is enabled (CAN-2005-0258).
Alerts:
Gentoo 200503-02 2005-03-01

(Log in to post comments)

Copyright © 2009, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds