PHPBB Remote SQL Query Manipulation...

- AV AC AU C I A
发布: 2001-08-03
修订: 2025-04-13

phpBB is free, open-source, easy-to-use web forums software. An issue exists in phpBB which allows a remote attacker to manipulate SQL queries in such a way as to gain an administrative account with the service. This problem is due to improper validation of user-supplied input by certain variables in phpBB. This issue can be exploited by making a cleverly crafted web request that contains arbitrary user-supplied replacement values. One consequence of successful exploitation is that the attacker will be privy to user information.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息