Short Name |
HTTP:PHP:PHPBB:AVATAR-UPLOAD |
---|---|
Severity |
Warning |
Recommended |
No |
Category |
HTTP |
Keywords |
phpBB Avatar Upload |
Release Date |
2005/05/10 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in the upload avatar included with PHP Bulletin Board (PHPBB). Attackers can use the avatar to obtain sensitive information.
phpBB is affected by an arbitrary file disclosure vulnerability. This issue arises due to an input validation error allowing an attacker to disclose files in the context of a Web server running the application. This may allow the attacker to gain access to sensitive data that may be used to carry out further attacks against a vulnerable computer. A successful attack requires the attacker to have a user account and the presence of some non-default settings allowing for the uploading of remote avatars. phpBB 2.0.11 and prior versions are affected by this issue.