CVE-2002-2346: Infoleak
Published Dec 31, 2002
·Updated
phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.
Affected Software
4 affected components
phpBB phpBB=2.0
phpBB phpBB=2.0.1
phpBB phpBB=2.0.2
phpBB phpBB=2.0.3
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 29, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2346?
CVE-2002-2346 is considered a moderate severity vulnerability as it allows remote attackers to expose client IP addresses.
2
How do I fix CVE-2002-2346?
To fix CVE-2002-2346, upgrade phpBB to version 2.0.4 or later where this vulnerability has been addressed.
3
What versions of phpBB are affected by CVE-2002-2346?
CVE-2002-2346 affects phpBB versions 2.0 through 2.0.3.
4
What type of vulnerability is CVE-2002-2346?
CVE-2002-2346 is a security vulnerability related to information disclosure.
5
Can CVE-2002-2346 be exploited remotely?
Yes, CVE-2002-2346 can be exploited remotely by attackers to obtain client IP addresses.