PhpBB 'feed.php' Security Bypass Vulnerability
BID:38599
Info
PhpBB 'feed.php' Security Bypass Vulnerability
| Bugtraq ID: | 38599 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2010 12:00AM |
| Updated: | Mar 08 2010 12:00AM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
phpBB Group phpBB 3.0.7 |
| Not Vulnerable: |
phpBB Group phpBB 3.0.7-PL1 |
Discussion
PhpBB 'feed.php' Security Bypass Vulnerability
PhpBB is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security restrictions, view restricted content, and perform unauthorized actions.
PhpBB 3.0.7 is vulnerable; other versions may also be affected.
PhpBB is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security restrictions, view restricted content, and perform unauthorized actions.
PhpBB 3.0.7 is vulnerable; other versions may also be affected.
Exploit / POC
PhpBB 'feed.php' Security Bypass Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
PhpBB 'feed.php' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
phpBB Group phpBB 3.0.7
Solution:
Updates are available. Please see the references for more information.
phpBB Group phpBB 3.0.7
-
phpBB Group phpBB-3.0.7-PL1.tar.bz2
http://www.phpbb.com/files/release/phpBB-3.0.7-PL1.tar.bz2 -
phpBB Group phpBB-3.0.7-PL1.zip
http://www.phpbb.com/files/release/phpBB-3.0.7-PL1.zip
References
PhpBB 'feed.php' Security Bypass Vulnerability
References:
References:
- phpBB Homepage (PhpBB)
- PhpBB Security Advisory: phpBB 3.0.7-PL1 released (PhpBB)