phpBB Avatar Upload HTML Injection Vulnerability

Solution:
The vendor has acknowledged this vulnerability and will be releasing a patch in the next release (version 2.0.18).

Debian has released advisory DSA 925-1 to address various issues in phpBB. Please see the referenced advisory for more information.



 

Privacy Statement
Copyright 2010, SecurityFocus