CVE-2008-7143: Infoleak
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7143?
CVE-2008-7143 is rated as a high severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2008-7143?
To fix CVE-2008-7143, upgrade to a version of phpBB that is not affected, as the vulnerability is present in version 2.0.23.
What impact does CVE-2008-7143 have on affected systems?
CVE-2008-7143 allows remote attackers to hijack user sessions, potentially leading to unauthorized access.
Is CVE-2008-7143 still a risk for users of phpBB 2.0.23?
Yes, CVE-2008-7143 remains a risk for any systems still using phpBB version 2.0.23.
What type of attacks are possible due to CVE-2008-7143?
CVE-2008-7143 enables attackers to perform session hijacking attacks through crafted URLs in thread posts.