PT-2005-1337 · Phpbb · Phpbb
Publicado
2005-02-22
·
Atualizado
2008-09-10
·
CVE-2005-0259
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpBB versions 2.0.11 and possibly other versions
Description
The issue allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file. This is possible when remote avatars and avatar uploading are enabled.
Recommendations
For phpBB version 2.0.11, consider disabling the remote avatar and avatar uploading features until a fix is available. As a temporary workaround, restrict access to the avatar upload functionality to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpbb