CVE-2004-0729: Medium severity Phpbb Group Phpbb vulnerability
Published Jul 23, 2004
·Updated
PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) categoryrows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.
Affected Software
2 affected components
Phpbb Group Phpbb=2.0.8
Phpbb Group Phpbb=2.0.8a
Event History
Jul 23, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0729?
CVE-2004-0729 is classified as a medium severity vulnerability.
2
How do I fix CVE-2004-0729?
To fix CVE-2004-0729, upgrade PhpBB to version 2.0.9 or later.
3
What vulnerabilities are associated with CVE-2004-0729?
CVE-2004-0729 allows remote attackers to reveal sensitive information through specific parameters.
4
Who is affected by CVE-2004-0729?
Any PhpBB version 2.0.8 or 2.0.8a users are affected by CVE-2004-0729.
5
What kind of information can be leaked due to CVE-2004-0729?
CVE-2004-0729 can leak the full server path in error messages.