View Single Post
  #1  
Old 24th Dec 04, 06:00 AM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,858
NewsBot will become famous soon enough
Massive vulnerability discovered in phpBB
Exploitation of phpBB highlight parameter vulnerability

Original release date: December 21, 2004
Last revised: December 22, 2004
Source: US-CERT
Systems Affected: phpBB versions 2.0.10 and prior.

OverviewThe software phpBB contains an input validation problem in how it processes a parameter contained in URLs. An intruder can deface a phpBB website, execute arbitrary commands, or gain administrative privileges on a compromised bulletin board.

News source: ieXbeta
Full story: View Here