Korean
<< Back
VID 21433
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The PunBB, according to its version number, has an information disclosure vulnerability via the search dropdown list. PunBB is a freely available, open source PHP-based bulletin board software. PunBB versions prior to 1.1.5 contain a flaw that may lead to an unauthorized information disclosure. The search dropdown list displays protected forums to unauthorized users.

* Note: This check solely relied on the version number of the PunBB installed on the remote web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=7974
http://www.punbb.org/changelogs/1.1.4_to_1.1.5.txt

* Platforms Affected:
Rickard Andersson, PunBB prior to 1.1.5
Any operating system Any version
Recommendation Upgrade to the latest version of PunBB (1.1.5 or later), available from the PunBB Download Web site at http://www.punbb.org/downloads.php
Related URL (CVE)
Related URL 11841 (SecurityFocus)
Related URL 18534 (ISS)