Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

phpBB2 Unauthorized Administrative Access Vulnerability

A vulnerability has been discovered in phpBB2 which may allow an unauthorized attacker to gain administrative privileges.

By sending a maliciously constructed post to a vulnerable forum resource, it is possible for an unauthorized user to grant 'administrator' privileges to arbitrary users.

Exploiting this issue could allow a remote attacker to gain complete control of a target forum.

It has been reported that third party utilities that use phpBB v2.0.0 may also be vulnerable to this issue.







 

Privacy Statement
Copyright 2008, SecurityFocus