phpBB Arbitrary File Disclosure Vulnerability

Posted on Wednesday, February 23, 2005 @ 15:37:02 CST in Security
by Raven

crypto writes:  
Security Alert: phpBB Group phpBB Arbitrary File Disclosure Vulnerability! The remote exploitation of an input validation vulnerability in the phpBB Group's phpBB2 bulletin board system allows attackers to read the contents of arbitrary system files under the privileges of the web server.

Exploitation of this vulnerability allows remote attackers to view arbitrary system files under the privileges of the underlying web server. An attacker must have, or be able to create an account on the target system. Non-default settings must also be enabled for exploitation to be possible. Upon successful exploitation an attacker may be able to further compromise the system by gleaning system information that would otherwise be inaccessible to the attacker.
More information:
  • idefense
  • phpbb.com
  • mitre.orgNote:
    Chatserv believes that these issues have been fixed in 2.0.12. I am posting this for awareness, though, in the event you haven't fixed yours yet :)
  •  
     
    click Related        click Share
     
     

    Re: phpBB Arbitrary File Disclosure Vulnerability (Score: 1)
    by chatserv on Wednesday, February 23, 2005 @ 21:00:40 CST

    (User Info | Send a Message) http://www.scriptheaven.net

    Having checked into it, yes, it has been addressed in phpBB 2.0.12

     
    News ©

    Site Info

    Last SeenLast Seen
    • kguske
    • nextgen
    Server TrafficServer Traffic
    • Total: 501,108,029
    • Today: 224,164
    Server InfoServer Info
    • Feb 28, 2025
    • 08:01 pm CST