First published: Mon Mar 23 2009(Updated: )
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpbb/phpbb | <3.0.4 | 3.0.4 |
phpBB | =3.0.2 | |
phpBB | =3.0.1 | |
phpBB | =3.0.0 | |
phpBB | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6507 has a medium severity rating due to its ability to expose sensitive information.
To fix CVE-2008-6507, upgrade phpBB to version 3.0.4 or later.
CVE-2008-6507 affects phpBB versions 3.0.0 through 3.0.3.
CVE-2008-6507 can be exploited through attacks aiming to access private messages in password-protected forums.
Yes, all users of vulnerable phpBB versions should remediate CVE-2008-6507 to protect sensitive information.