Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Gentoo: 200306-15 Severe: phpBB SQL Injection Remote Threat

gentoo
Calendar Grey July 1, 2003
Dist Gentoo Esm H88
A new Gentoo security advisory reveals a critical phpBB vulnerability, enabling remote attackers to extract password hashes via SQL injection. Quick updates are recommended.
QL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200306-15


quote from cve: "SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/phpbb upgrade to phpbb-2.0.5 as follows
emerge sync emerge phpbb emerge clean
aliz@gentoo.org - GnuPG key is available at robbat2@gentoo.org

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : phpbb
SUMMARY : sql injection
DATE : 2003-06-28 20:22 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =phpbb-2.0.5
CVE : CAN-2003-0486

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here