PT-2009-2612 · Phpbb · Phpbb
Publicado
2009-09-01
·
Atualizado
2018-10-11
·
CVE-2008-7143
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpBB version 2.0.23
Description
The issue allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header, when the moderator or administrator closes a thread. This occurs because the session ID is included in a request to "modcp.php".
Recommendations
For phpBB version 2.0.23, consider restricting access to the "modcp.php" module to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using images from remote hosts in posts, especially when closing threads, to prevent potential session hijacking.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phpbb