CVE-2008-3224: Critical severity phpbb prillian vulnerability
Published Jul 18, 2008
·Updated
Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within loginbox()."
Affected Software
9 affected components
phpBB phpbb<=3.0.1
phpBB phpbb=3.0-rc1
phpBB phpbb=3.0-rc2
phpBB phpbb=3.0-rc3
phpBB phpbb=3.0-rc4
phpBB phpbb=3.0-rc5
phpBB phpbb=3.0-rc7
phpBB phpbb=3.0-rc8
phpBB phpbb=3.0.0
Event History
Jul 18, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3224?
The severity of CVE-2008-3224 is currently unspecified, as the exact impact and attack vectors are unknown.
2
How do I fix CVE-2008-3224?
To fix CVE-2008-3224, upgrade phpBB to version 3.0.1 or later, as this is the first patched release.
3
What versions of phpBB are affected by CVE-2008-3224?
CVE-2008-3224 affects phpBB versions prior to 3.0.1, including various release candidates and version 3.0.0.
4
What attack vectors are associated with CVE-2008-3224?
CVE-2008-3224 may involve unidentified attack vectors related to the use of urls in the login_box() function.
5
Is there a workaround for CVE-2008-3224?
Currently, no official workarounds are provided for CVE-2008-3224, the best mitigation is to upgrade to a secure version.