SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#774686

phpBB vulnerable to file disclosure

Overview

The phpBB input validation methods may fail to sanitize user input resulting in a disclosure of arbitrary file data.

I. Description

phpBB is a customizable open source bulletin board package. It contains functionality that allows users to specify graphic files for use as "avatars." These files may be located on a remote server or on a filesystem. However, a local file upload path using the default, temporary remote server name can cause the remote phpBB server to interpret a file local to the server as the avatar file. This file will then be made available to theuser for download or viewing.

II. Impact

If the remote avatar and remote avatar uploading functions are enabled (which are disabled by default), a remote, authenticated attacker who is allowed to specify remote avatars may be able to access arbitrary files on the phpBB server with the permissions of the web server.

III. Solution

Apply an update

phpBB versions 2.0.12 and later do not contain this flaw. The phpBB web page contains additional information and downloads.

As a workaround, administrators may disable remote avatars and remote avatar uploading. These features are disabled by default.

Systems Affected

VendorStatusDate NotifiedDate Updated
PHPBBVulnerable24-Feb-2005

References


http://www.idefense.com/application/poi/display?id=204&type=vulnerabilities
http://secunia.com/advisories/14362/
http://www.phpbb.com/phpBB/viewtopic.php?t=265423

Credit

Thanks to AnthraX101 for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

Date Public:2005-02-22
Date First Published:2005-02-25
Date Last Updated:2005-03-17
CERT Advisory: 
CVE-ID(s):CAN-2005-0259
NVD-ID(s):CAN-2005-0259
US-CERT Technical Alerts: 
Metric:3.75
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader