PT-2005-5044 · Phpbb · Phpbb

Cxib8O3

+1

·

Publicado

2005-12-20

·

Atualizado

2018-10-19

·

CVE-2005-4358

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpBB version 2.0.18
Description The issue allows remote attackers to obtain the installation path of phpBB. This is achieved by making a direct request to the 'admin/admin disallow.php' endpoint with a non-empty setmodules parameter. The request causes an invalid append sid function call, resulting in the installation path being leaked in an error message.
Recommendations For phpBB version 2.0.18, consider restricting access to the 'admin/admin disallow.php' endpoint until a fix is available. As a temporary workaround, avoid using the setmodules parameter in requests to this endpoint to minimize the risk of path disclosure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4358

Produtos afetados

Phpbb