Korean
<< Back
VID 21636
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description A version of phpBB software which is older or as old as than version 2.0.15 is detected as installed on the host. phpBB is a open-source bulletin board software package, which uses MySQL, MS-SQL, PostgreSQL or Access/ODBC database. phpBB2 2.0.15 versions and earlier are vulnerable to a remote PHP script injection vulnerability, caused by improper filtering of user supplied input passed to the "highlight" parameter of the "viewtopic.php" script. This vulnerability could allow a remote attacker to execute arbitrary commands in the context of the web server that is hosting the vulnerable software.

* Note: This check solely relied on the version number of the phpBB software installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.phpbb.com/phpBB/viewtopic.php?t=302011
http://www.securityfocus.com/archive/1/403631
http://secunia.com/advisories/15845/

* Platforms Affected:
phpBB Group, phpBB versions prior to 2.0.16
Any operating system Any version
Recommendation Upgrade to the latest version of phpBB (2.0.16 or later), available from the phpBB Web site at http://www.phpbb.com/downloads.php
Related URL CVE-2005-2086 (CVE)
Related URL 14086 (SecurityFocus)
Related URL 21197 (ISS)