CVE-2005-0258: Medium severity Phpbb Group Phpbb vulnerability
Directory traversal vulnerability in (1) usercpregister.php and (2) usercpavatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0258?
CVE-2005-0258 has been classified as a moderate severity vulnerability due to its potential to allow file deletion.
How do I fix CVE-2005-0258?
To fix CVE-2005-0258, upgrade phpBB to version 2.0.12 or later, which resolves the directory traversal issue.
Which versions are affected by CVE-2005-0258?
CVE-2005-0258 affects phpBB versions up to 2.0.11, specifically versions 2.0.1 through 2.0.11.
What type of vulnerability is CVE-2005-0258?
CVE-2005-0258 is a directory traversal vulnerability that allows attackers to access files outside the intended directory.
Can CVE-2005-0258 lead to data loss?
Yes, CVE-2005-0258 can lead to data loss as it allows attackers to delete arbitrary files on the server.