First published: Sun Dec 31 2006(Updated: )
Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb | =2.0.21 | |
Phpbb Group Phpbb | =2.0.20 | |
Phpbb Group Phpbb | =1.2.4_rc3 | |
Phpbb Group Phpbb | =2.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-6841 is classified as unknown due to its lack of detailed impact information.
To fix CVE-2006-6841, it is recommended to upgrade to phpBB version 2.0.22 or later.
CVE-2006-6841 affects phpBB versions 2.0.21, 2.0.20, 2.0.18, and 1.2.4_rc3.
CVE-2006-6841 has remote attack vectors due to the lack of session checks in certain forms.
The main issue with CVE-2006-6841 is the lack of session verification, which may expose the application to unauthorized actions.