PT-2005-4213 · Php+1 · Php+1

Stefan Esser

·

Published

2005-11-01

·

Updated

2016-10-18

·

CVE-2005-3417

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpBB versions 2.0.17 and earlier
Description The issue allows remote attackers to modify global variables and bypass security mechanisms. This occurs because PHP does not define the associated HTTP * variables when the register long arrays directive is disabled.
Recommendations For phpBB versions 2.0.17 and earlier, consider enabling the register long arrays directive as a temporary workaround to prevent the modification of global variables. However, note that this directive is deprecated and its use is generally discouraged. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3417
DSA-925-1

Affected Products

Php
Phpbb