Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPBB2 Install.PHP Remote File Include Vulnerability

Solution:
Reportedly, exploitation of this type of vulnerability is not possible unless both 'allow_url_fopen' and 'register_globals' are enabled in the local site PHP configuration.

It is good practice to disable any unneeded options.

The installation document distributed with phpBB instructs users to delete 'install.php', 'upgrade.php' and 'update_to_FINAL.php' files.








 

Privacy Statement
Copyright 2009, SecurityFocus