Retired: phpBB Forum ID Security Bypass Vulnerability
BID:37882
Info
Retired: phpBB Forum ID Security Bypass Vulnerability
| Bugtraq ID: | 37882 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2010 12:00AM |
| Updated: | Jan 29 2010 03:21PM |
| Credit: | nickvergessen |
| Vulnerable: |
phpBB Group phpBB 3.0.4 phpBB Group phpBB 3.0.3 phpBB Group phpBB 3.0.2 phpBB Group phpBB 3.0.1 phpBB Group phpBB 3.0 |
| Not Vulnerable: |
phpBB Group phpBB 3.0.5 |
Discussion
Retired: phpBB Forum ID Security Bypass Vulnerability
phpBB is prone to a security-bypass vulnerability.
Attackers can exploit this vulnerability to bypass certain security restrictions and gain unauthorized access to the affected application.
Versions prior to phpBB 3.0.5 are vulnerable.
Reports indicate that issue is not exploitable; therefore this BID is being retired.
phpBB is prone to a security-bypass vulnerability.
Attackers can exploit this vulnerability to bypass certain security restrictions and gain unauthorized access to the affected application.
Versions prior to phpBB 3.0.5 are vulnerable.
Reports indicate that issue is not exploitable; therefore this BID is being retired.
Exploit / POC
Retired: phpBB Forum ID Security Bypass Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
References
Retired: phpBB Forum ID Security Bypass Vulnerability
References:
References:
- phpBB Changelog (phpBB Group)
- phpBB Homepage (phpBB Group)