First published: Mon Feb 28 2005(Updated: )
viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb | =2.0.5 | |
Phpbb Group Phpbb | =2.0.7a | |
Phpbb Group Phpbb | =2.0.8 | |
Phpbb Group Phpbb | =2.0.11 | |
Phpbb Group Phpbb | =2.0.1 | |
Phpbb Group Phpbb | =2.0.3 | |
Phpbb Group Phpbb | =2.0_rc2 | |
Phpbb Group Phpbb | =2.0_rc1 | |
Phpbb Group Phpbb | =2.0.4 | |
Phpbb Group Phpbb | =2.0.9 | |
Phpbb Group Phpbb | =2.0.7 | |
Phpbb Group Phpbb | =2.0.8a | |
Phpbb Group Phpbb | =2.0.6d | |
Phpbb Group Phpbb | =2.0.2 | |
Phpbb Group Phpbb | =2.0.10 | |
Phpbb Group Phpbb | =2.0.6c | |
Phpbb Group Phpbb | =2.0_rc4 | |
Phpbb Group Phpbb | =2.0.6 | |
Phpbb Group Phpbb | =2.0.0 | |
Phpbb Group Phpbb | =2.0_rc3 | |
Phpbb Group Phpbb | =2.0_beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0603 is classified as a medium severity vulnerability.
To fix CVE-2005-0603, upgrade phpBB to version 2.0.13 or later.
CVE-2005-0603 affects all versions of phpBB 2.0.12 and earlier.
CVE-2005-0603 allows remote attackers to reveal sensitive information through PHP error messages.
CVE-2005-0603 affects the viewtopic.php script in phpBB.