PHPBB_HIGHLIGHT_PARAM_EXPLOIT
Data de publicação: 04 fevereiro 2011
Schweregrad: : Crítico
Data do informe: 04 fevereiro 2011
Descrição
A Remote Command Execution vulnerability has been found in phpBB version 2.0.10 and below. Inputs to several HTTP requests are not validated by this script. Once this vulnerability is successfully exploited, a remote malicious user can view the content of arbitrary files on the system with the privileges of the Web server.
phpBB is an open source bulletin board system.
Exposição das informações
Download the latest NVW pattern file from this site:
http://www.trendmicro.com/download/product.asp?productid=45
Software infectado e versão:
- phpBB version 2.0.10 and below