phpBB Insecure File Permissions Vulnerability
BID:62267
Info
phpBB Insecure File Permissions Vulnerability
| Bugtraq ID: | 62267 |
| Class: | Design Error |
| CVE: |
CVE-2013-5724 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2013 12:00AM |
| Updated: | Mar 19 2015 09:22AM |
| Credit: | Andreas Beckmann |
| Vulnerable: |
phpBB Group phpBB 3.0.7 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
phpBB Insecure File Permissions Vulnerability
phpBB is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and overwrite certain files. Information obtained may aid in further attacks.
phpBB is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and overwrite certain files. Information obtained may aid in further attacks.
Exploit / POC
phpBB Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
phpBB Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.