PHPBB2 Avatar Images Information Disclosure Vulnerability
BID:5923
Info
PHPBB2 Avatar Images Information Disclosure Vulnerability
| Bugtraq ID: | 5923 |
| Class: | Design Error |
| CVE: |
CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 CVE-2002-2346 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2002 12:00AM |
| Updated: | Mar 19 2015 09:08AM |
| Credit: | Discovery of this vulnerability credited to Priamus <[email protected]>. |
| Vulnerable: |
phpBB Group phpBB 2.0.3 phpBB Group phpBB 2.0.2 phpBB Group phpBB 2.0.1 phpBB Group phpBB 2.0 .0 |
| Not Vulnerable: | |
Discussion
PHPBB2 Avatar Images Information Disclosure Vulnerability
It has been reported that phpBB2 reveals a user's IP address. This vulnerability is due to phpBB2's file naming scheme for avatar files.
When a user elects to upload an avatar file to a system using phpBB2, the system will save the file with a random name. This random name consists of the user's IP address, encoded in hexadecimal values, followed by other characters.
A malicious attacker can exploit this vulnerability to find out IP addresses of the users of the system hosting phpBB2 forums.
It has been reported that phpBB2 reveals a user's IP address. This vulnerability is due to phpBB2's file naming scheme for avatar files.
When a user elects to upload an avatar file to a system using phpBB2, the system will save the file with a random name. This random name consists of the user's IP address, encoded in hexadecimal values, followed by other characters.
A malicious attacker can exploit this vulnerability to find out IP addresses of the users of the system hosting phpBB2 forums.
Exploit / POC
PHPBB2 Avatar Images Information Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
PHPBB2 Avatar Images Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.