PHPBB Unauthorized HTTP Proxy Vulnerability
BID:17965
CVE-2006-4450 |Info
PHPBB Unauthorized HTTP Proxy Vulnerability
| Bugtraq ID: | 17965 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2006 12:00AM |
| Updated: | May 16 2006 05:39PM |
| Credit: | rgod is credited with the discoveyr of this vulnerability. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
PHPBB Unauthorized HTTP Proxy Vulnerability
phpBB is prone to a vulnerability that could permit the application to become an unauthorized HTTP proxy.
An attacker can exploit this issue to manipulate phpBB into becoming an HTTP proxy.
phpBB is prone to a vulnerability that could permit the application to become an unauthorized HTTP proxy.
An attacker can exploit this issue to manipulate phpBB into becoming an HTTP proxy.
Exploit / POC
PHPBB Unauthorized HTTP Proxy Vulnerability
This issue can be exploited through a web client.
The following proof-of-concept URI is available:
This issue can be exploited through a web client.
The following proof-of-concept URI is available:
Solution / Fix
PHPBB Unauthorized HTTP Proxy Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
PHPBB Unauthorized HTTP Proxy Vulnerability
References:
References:
- phpBB Homepage (phpBB)
- PHPBB 2.0.20 persistent issues with avatars (rgod)