4.6
CVSSv2

CVE-2006-4758

Published: 13/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P

Vulnerability Summary

phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.21

Vendor Advisories

Several remote vulnerabilities have been discovered in phpBB, a web based bulletin board The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0471 Private messaging allowed cross site request forgery, making it possible to delete all private messages of a user by sending them to a crafted web page CVE-2 ...