Vulnerabilities > CVE-2006-4450 - Unspecified vulnerability in PHPbb Group PHPbb 2.0.20
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | PHPBB 2.0.20 Unauthorized HTTP Proxy Vulnerability. CVE-2006-4450. Webapps exploit for php platform |
id | EDB-ID:27863 |
last seen | 2016-02-03 |
modified | 2006-05-12 |
published | 2006-05-12 |
reporter | rgod |
source | https://www.exploit-db.com/download/27863/ |
title | PHPBB 2.0.20 Unauthorized HTTP Proxy Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1066.NASL |
description | It was discovered that phpbb2, a web-based bulletin board, does insufficiently sanitise values passed to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22608 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22608 |
title | Debian DSA-1066-1 : phpbb2 - missing input sanitising |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2006-05/0238.html
- http://archives.neohapsis.com/archives/bugtraq/2006-05/0238.html
- http://secunia.com/advisories/20093
- http://secunia.com/advisories/20093
- http://securityreason.com/securityalert/1470
- http://securityreason.com/securityalert/1470
- http://www.securityfocus.com/bid/17965
- http://www.securityfocus.com/bid/17965
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26537
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26537