PT-2005-4213 · Php+1 · Php+1
Stefan Esser
·
Published
2005-11-01
·
Updated
2016-10-18
·
CVE-2005-3417
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpBB versions 2.0.17 and earlier
Description
The issue allows remote attackers to modify global variables and bypass security mechanisms. This occurs because PHP does not define the associated HTTP * variables when the register long arrays directive is disabled.
Recommendations
For phpBB versions 2.0.17 and earlier, consider enabling the register long arrays directive as a temporary workaround to prevent the modification of global variables. However, note that this directive is deprecated and its use is generally discouraged. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php
Phpbb