PT-2005-4213 · Php+1 · Php+1
Stefan Esser
·
Publicado
2005-11-01
·
Atualizado
2016-10-18
·
CVE-2005-3417
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpBB versions 2.0.17 and earlier
Description
The issue allows remote attackers to modify global variables and bypass security mechanisms. This occurs because PHP does not define the associated HTTP * variables when the register long arrays directive is disabled.
Recommendations
For phpBB versions 2.0.17 and earlier, consider enabling the register long arrays directive as a temporary workaround to prevent the modification of global variables. However, note that this directive is deprecated and its use is generally discouraged. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php
Phpbb