feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.
References
Configurations
History
21 Nov 2024, 01:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2010/05/16/1 - | |
References | () http://www.openwall.com/lists/oss-security/2010/05/18/6 - | |
References | () http://www.phpbb.com/community/viewtopic.php?f=14&t=2014195 - Patch, Vendor Advisory |
Information
Published : 2010-05-19 22:30
Updated : 2024-11-21 01:14
NVD link : CVE-2010-1627
Mitre link : CVE-2010-1627
CVE.ORG link : CVE-2010-1627
JSON object : View
Products Affected
phpbb
- phpbb
CWE
CWE-264
Permissions, Privileges, and Access Controls