PT-2004-2239 · Phpbb · Phpbb

Psotfx

·

Publicado

2004-11-12

·

Atualizado

2017-07-11

·

CVE-2004-1315

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: phpBB versions prior to 2.0.11
Description: The issue allows remote attackers to execute arbitrary PHP code by exploiting the improper URL decoding of the highlight parameter in the viewtopic.php file. This is achieved by double-encoding the highlight value, which results in special characters being inserted into the processed result. The vulnerability was exploited by the Santy.A worm.
Recommendations: For versions prior to 2.0.11, update to version 2.0.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the viewtopic.php file or disabling the highlight parameter to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1315

Produtos afetados

Phpbb