PT-2005-4215 · Phpbb · Phpbb
Stefan Esser
·
Publicado
2005-11-01
·
Atualizado
2016-10-18
·
CVE-2005-3419
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpBB version 2.0.17
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
signature bbcode uid parameter in the usercp register.php file, which is not properly initialized.Recommendations
For phpBB version 2.0.17, consider restricting access to the usercp register.php file until a proper fix is applied, and ensure that all parameters, including
signature bbcode uid, are properly sanitized to prevent SQL injection attacks.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpbb