PT-2005-4215 · Phpbb · Phpbb

Stefan Esser

·

Publicado

2005-11-01

·

Atualizado

2016-10-18

·

CVE-2005-3419

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpBB version 2.0.17
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the signature bbcode uid parameter in the usercp register.php file, which is not properly initialized.
Recommendations For phpBB version 2.0.17, consider restricting access to the usercp register.php file until a proper fix is applied, and ensure that all parameters, including signature bbcode uid, are properly sanitized to prevent SQL injection attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3419
DSA-925-1

Produtos afetados

Phpbb