| VID |
21318 |
| Severity |
20 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The phpBB installed on the Web server has multiple Path Disclosure Vulnerabilities. The phpBB is a open-source bulletin board software package, which uses MySQL, MS-SQL, PostgreSQL or Access/ODBC database. The phpBB version 2.0.8 and possibly earlier versions are vulnerable to multiple Path Disclosure Vulnerabilities in the 'index.php', 'lang_faq.php', 'lang_bbcode.php', and 'lusercp_viewprofile.php' scripts. A remote attacker could cause phpBB to return an error that discloses the full path of the Web root directory by sending a specially-crafted URL to these vulnerable scripts. A remote attacker can use this information to perform further attack.
* References: http://archives.neohapsis.com/archives/bugtraq/2004-07/0170.html
* Platforms Affected: phpBB 2.0.8 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of phpBB (2.0.10 or later) from the phpBB Downloads Web page at http://www.phpbb.com/downloads.php |
| Related URL |
CVE-2004-0729 (CVE) |
| Related URL |
10738 (SecurityFocus) |
| Related URL |
16716,16720,16722,16723 (ISS) |
|