PT-2004-1809 · Phpbb · Phpbb

Janek Vind

+1

·

Publicado

2004-07-23

·

Atualizado

2017-07-11

·

CVE-2004-0729

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpBB version 2.0.8
Description The issue allows remote attackers to gain sensitive information. This is achieved by providing an invalid parameter to certain API endpoints, which then reveal the full path in an error message. Specifically, this can be done through the category rows parameter to "index.php", the faq parameter to "faq.php", or the ranksrow parameter to "profile.php".
Recommendations For phpBB version 2.0.8, consider restricting access to the vulnerable API endpoints "index.php", "faq.php", and "profile.php" until a fix is available. As a temporary workaround, avoid using the category rows, faq, and ranksrow parameters in these endpoints to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0729

Produtos afetados

Phpbb