Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rwq-m5m5-h79g

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

EPSS

Процентиль: 67%
0.00539
Низкий

Связанные уязвимости

ubuntu
почти 21 год назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

nvd
почти 21 год назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

debian
почти 21 год назад

phpBB 2.0.11, and possibly other versions, with remote avatars and ava ...

EPSS

Процентиль: 67%
0.00539
Низкий