Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rwq-m5m5-h79g

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

EPSS

Процентиль: 67%
0.00539
Низкий

Связанные уязвимости

ubuntu
больше 20 лет назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

nvd
больше 20 лет назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

debian
больше 20 лет назад

phpBB 2.0.11, and possibly other versions, with remote avatars and ava ...

EPSS

Процентиль: 67%
0.00539
Низкий