Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Gentoo GLSA-200507-03 High: phpBB Arbitrary Command Execution

gentoo
Calendar Grey July 4, 2005
Scroller Gentoo
Critical security advisory regarding phpBB command execution flaws and the recommended fix from Gentoo Linux.
A vulnerability in phpBB allows a remote attacker to execute arbitrary commands with the rights of the web server.

Summary

Gentoo Linux Security Advisory GLSA 200507-03 https://security.gentoo.org/ Severity: High Title: phpBB: Arbitrary command execution Date: July 04, 2005 Bugs: #97278 ID: 200507-03

Synopsis ======= A vulnerability in phpBB allows a remote attacker to execute arbitrary commands with the rights of the web server.
Background ========= phpBB is an Open Source bulletin board package.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpBB < 2.0.16 >= 2.0.16
========== Ron van Daal discovered that phpBB contains a vulnerability in the highlighting code.
Impact ===== Successful exploitation would grant an attacker unrestricted access to the PHP exec...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround