First published: Thu Mar 03 2005(Updated: )
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb | =2.0.5 | |
Phpbb Group Phpbb | =2.0.7a | |
Phpbb Group Phpbb | =1.2.1 | |
Phpbb Group Phpbb | =2.0.8 | |
Phpbb Group Phpbb | =2.0.11 | |
Phpbb Group Phpbb | =1.4.1 | |
Phpbb Group Phpbb | =1.4.4 | |
Phpbb Group Phpbb | =2.0.1 | |
Phpbb Group Phpbb | =2.0.3 | |
Phpbb Group Phpbb | =2.0_rc2 | |
Phpbb Group Phpbb | =1.4.2 | |
Phpbb Group Phpbb | =2.0_rc1 | |
Phpbb Group Phpbb | =2.0.4 | |
Phpbb Group Phpbb | =2.0.12 | |
Phpbb Group Phpbb | =2.0.9 | |
Phpbb Group Phpbb | =2.0.7 | |
Phpbb Group Phpbb | =2.0.8a | |
Phpbb Group Phpbb | =2.0.6d | |
Phpbb Group Phpbb | =2.0.2 | |
Phpbb Group Phpbb | =1.0.0 | |
Phpbb Group Phpbb | =2.0.10 | |
Phpbb Group Phpbb | =2.0.6c | |
Phpbb Group Phpbb | =1.2.0 | |
Phpbb Group Phpbb | =1.4.0 | |
Phpbb Group Phpbb | =2.0_rc4 | |
Phpbb Group Phpbb | =2.0.6 | |
Phpbb Group Phpbb | =2.0.0 | |
Phpbb Group Phpbb | =2.0_rc3 | |
Phpbb Group Phpbb | =2.0_beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0614 has a high severity rating due to its ability to allow remote attackers to gain administrator privileges.
To fix CVE-2005-0614, you should upgrade to a newer version of phpBB that is not vulnerable, such as phpBB 2.0.13 or later.
CVE-2005-0614 affects phpBB versions 2.0.12 and earlier, as well as various other earlier versions.
CVE-2005-0614 enables remote code execution attacks that can lead to unauthorized access to the administrator account.
You can determine your vulnerability by checking your phpBB version against the affected versions listed in the CVE-2005-0614 description.