CVE-2010-1630
HIGH severity · CVSS 7.5
7.5CVSS HIGH
Summary
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)1%
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://www.phpbb.com/community/viewtopic.php?f=14&p=9764445Advisory
- http://github.com/phpbb/phpbb3/commit/4ea3402f9363c9259881bc8ea6ce7fc6cb212657
- http://www.openwall.com/lists/oss-security/2010/05/16/1
- http://www.openwall.com/lists/oss-security/2010/05/18/12
- http://www.openwall.com/lists/oss-security/2010/05/19/5