PHPBB2 Install.PHP Remote File Include Vulnerability
BID:5038
Info
PHPBB2 Install.PHP Remote File Include Vulnerability
| Bugtraq ID: | 5038 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2002 12:00AM |
| Updated: | Jun 17 2002 12:00AM |
| Credit: | Credited to morris Chang <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 2.0.1 phpBB Group phpBB 2.0 .0 phpBB Group phpBB 2.0 RC4 phpBB Group phpBB 2.0 RC3 phpBB Group phpBB 2.0 RC2 phpBB Group phpBB 2.0 RC1 |
| Not Vulnerable: | |
Exploit / POC
PHPBB2 Install.PHP Remote File Include Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHPBB2 Install.PHP Remote File Include Vulnerability
Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
The installation document distributed with phpBB instructs users to delete 'install.php', 'upgrade.php' and 'update_to_FINAL.php' files.
Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
The installation document distributed with phpBB instructs users to delete 'install.php', 'upgrade.php' and 'update_to_FINAL.php' files.