AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 09, 2009, 05:40:59 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5372 Members
Latest Member: AAEffessemparee
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PhpBB Alerts  |  Topic: PHPBB - MUST Upgrade to 2.0.13 ASAP! 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: PHPBB - MUST Upgrade to 2.0.13 ASAP!  (Read 1192 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
PHPBB - MUST Upgrade to 2.0.13 ASAP!
« on: February 28, 2005, 12:09:53 PM »

 K-OTik Security Advisory : KOTIK/ADV-2005-0212
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : High
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-02-28

 * Technical Description *

Two vulnerabilities were reported in phpBB, which may be exploited by attackers to determine the installation path or bypass certain security features. The first problem resides in the "autologinid" (includes/sessions.php) variable and could be exploited by malicious users to gain administrator rights. The second flaw resides in the "viewtopic.php" script, and could be exploited to disclose the webroot path.

 * Affected Products *

phpBB version 2.0.12 and prior

 * Solution *

phpBB version 2.0.13 :
http://www.phpbb.com/downloads.php

 * References *

http://www.k-otik.com/english/advisories/2005/0212
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=267563
« Last Edit: February 28, 2005, 12:12:01 PM by AlphaWolf » Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PhpBB Alerts  |  Topic: PHPBB - MUST Upgrade to 2.0.13 ASAP! « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!