5
CVSSv2

CVE-2006-2219

Published: 08/02/2007 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote malicious users to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.20