CVE-2006-4758: Medium severity Phpbb Group Phpbb vulnerability
phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/adminboard.php with an avatarpath parameter ending in .php%00.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4758?
CVE-2006-4758 is considered a high severity vulnerability as it allows remote authenticated users to upload arbitrary files.
How do I fix CVE-2006-4758?
To fix CVE-2006-4758, upgrade PHPBB to a version that is not vulnerable, ideally version 2.0.22 or later.
What are the potential risks of CVE-2006-4758?
The potential risks of CVE-2006-4758 include unauthorized file uploads, which could lead to system compromise or data breaches.
Who is affected by CVE-2006-4758?
CVE-2006-4758 affects users of phpBB version 2.0.21 who have allowed remote authenticated administrative access.
What types of attacks can occur due to CVE-2006-4758?
Due to CVE-2006-4758, attackers can exploit the vulnerability to upload malicious PHP files that can be executed on the server.