|
-
October 6th, 2003, 02:23 AM
#4
phpBB 2.0.6 and earlier has three security vulnerabilities:
BID-8570: XSS->phpBB 2.0.6 and earlier
CAN-2003-0486: SQL Injection-> phpBB 2.0.4
BID-7932: Script Injection->phpBB 2.0.0-2.0.4
There are workarounds available for all of these vulnerabilities. The most serious are CAN-2003-0486 which would allow an attacker to steal the hash of the password for the admin user and BID-7932 which allows an attacker to run arbitrary code.
$person!=$kiddie or die(\"Alas, die you hotmail hacker!!\");
SecureVision
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|