PT-2005-1337 · Phpbb · Phpbb

Publicado

2005-02-22

·

Atualizado

2008-09-10

·

CVE-2005-0259

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpBB versions 2.0.11 and possibly other versions
Description The issue allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file. This is possible when remote avatars and avatar uploading are enabled.
Recommendations For phpBB version 2.0.11, consider disabling the remote avatar and avatar uploading features until a fix is available. As a temporary workaround, restrict access to the avatar upload functionality to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0259

Produtos afetados

Phpbb