BugTraq
[phpbb <= 2.0.13 full path disclosure & directory listing] Mar 18 2005 07:21PM
JoCaNoR SeCuRiTy TeaM (jocanor gmail com) (1 replies)
RE: [phpbb <= 2.0.13 full path disclosure & directory listing] Mar 18 2005 10:11PM
Paul S. Owen (paul0x01 starstreak net)
> [phpbb <= 2.0.13 full path disclosure & directory listing]
>
> Author: Jocanor
> Date= 18-03-2k5

This is _not_ an issue for phpBB 2.0.x. The 2.0.x line does _not_ support
Oracle, it will not function using that DB without significant modification.
Usually the oracle.php layer is not included, unfortunately it "snuck" into
the latest release. However as noted it will not work and thus this
"exploit" cannot achieve anything unless the version of phpBB installed has
been explicitly modified (using third party Mods) to function with Oracle.

psoTFX - Paul S. Owen - phpBB Group

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus