10
CVSSv2

CVE-2006-6841

Published: 31/12/2006 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Certain forms in phpBB prior to 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.18

phpbb group phpbb 2.0.21

phpbb group phpbb 1.2.4_rc3

phpbb group phpbb 2.0.20

Vendor Advisories

Several remote vulnerabilities have been discovered in phpBB, a web based bulletin board The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0471 Private messaging allowed cross site request forgery, making it possible to delete all private messages of a user by sending them to a crafted web page CVE-2 ...