PT-2005-4213 · Php+1 · Php+1

Stefan Esser

·

Publicado

2005-11-01

·

Atualizado

2016-10-18

·

CVE-2005-3417

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpBB versions 2.0.17 and earlier
Description The issue allows remote attackers to modify global variables and bypass security mechanisms. This occurs because PHP does not define the associated HTTP * variables when the register long arrays directive is disabled.
Recommendations For phpBB versions 2.0.17 and earlier, consider enabling the register long arrays directive as a temporary workaround to prevent the modification of global variables. However, note that this directive is deprecated and its use is generally discouraged. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3417
DSA-925-1

Produtos afetados

Php
Phpbb