CVE-2006-2220: Input Validation
phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2220?
CVE-2006-2220 is classified as a moderate severity vulnerability due to its potential to leak sensitive information.
How do I fix CVE-2006-2220?
To fix CVE-2006-2220, upgrade phpBB to a version that includes a patch for input validation vulnerabilities.
What is affected by CVE-2006-2220?
CVE-2006-2220 specifically affects phpBB version 2.0.20.
What does CVE-2006-2220 exploit?
CVE-2006-2220 exploits improper input validation, allowing for SQL injection via negative LIMIT specifications.
Who can be impacted by CVE-2006-2220?
Remote attackers can be impacted by CVE-2006-2220 if they target vulnerable installations of phpBB version 2.0.20.