Vulnerability Name: | CVE-2006-4758 (CCN-28884) | ||||||||||||||||
Assigned: | 2006-09-11 | ||||||||||||||||
Published: | 2006-09-11 | ||||||||||||||||
Updated: | 2018-10-17 | ||||||||||||||||
Summary: | phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00. Successful exploitation requires that the attacker has Administrative rights. | ||||||||||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P) 3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Sep 11 2006 - 16:33:56 CDT ShAnKaR: multiple PHP application poison NULL byte vulnerability Source: CONFIRM Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=388120 Source: MITRE Type: CNA CVE-2006-4758 Source: CCN Type: SA22188 phpBB "avatar_path" PHP Code Execution Vulnerability Source: SECUNIA Type: UNKNOWN 22188 Source: SECUNIA Type: UNKNOWN 28871 Source: DEBIAN Type: UNKNOWN DSA-1488 Source: DEBIAN Type: DSA-1488 phpbb2 -- several vulnerabilities Source: CCN Type: OSVDB ID: 29493 phpBB admin/admin_board.php avatar_path Variable Arbitrary File Upload PHP Code Execution Source: CCN Type: phpBB Web site phpBB:: Creating Communities Source: MISC Type: UNKNOWN http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=489624 Source: MISC Type: Exploit http://www.security.nnov.ru/Odocument221.html Source: BUGTRAQ Type: UNKNOWN 20060911 ShAnKaR: multiple PHP application poison NULL byte vulnerability Source: BID Type: UNKNOWN 20347 Source: CCN Type: BID-20347 phpBB Avatar_Path PHP Code Execution Vulnerability Source: BID Type: UNKNOWN 21806 Source: CCN Type: BID-21806 PHPBB Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN phpbb-nullbyte-file-upload(28884) Source: XF Type: UNKNOWN phpbb-nullbyte-file-upload(28884) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |