Secunia Advisory SA14362phpBB Avatar Functions Information Disclosure and Deletion
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
AnthraX101 has reported two vulnerabilities in phpBB, which can be exploited by malicious users to disclose and delete sensitive information. 1) An input validation error in the upload handling of avatars can be exploited to disclose arbitrary files by simultaneously requesting to upload an avatar from both a local and a remote source, and specifying a local path in the "Upload Avatar from a URL:" field. Successful exploitation requires that "Enable remote avatars" and "Enable avatar uploading" are enabled (not default settings). 2) Input validation errors in "usercp_avatar.php" and "usercp_register.php" can in combination be exploited to delete arbitrary files via directory traversal attacks. Successful exploitation requires that "Enable gallery avatars" is enabled (not default setting). Some issues disclosing the full path to certain scripts have also been reported. The vulnerabilities have been reported in version 2.0.11. Prior versions may also be affected. Solution Provided and/or discovered by Other references Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
155 views | ![]() |
| Gentoo update for sarg | |
212 views | ![]() |
| Debian update for freetype | |