Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jrx-4wqj-328p

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.

EPSS

Процентиль: 62%
0.0043
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 16 лет назад

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.

debian
больше 16 лет назад

phpBB 2.0.23 includes the session ID in a request to modcp.php when th ...

EPSS

Процентиль: 62%
0.0043
Низкий

Дефекты

CWE-200