CVE-2010-1630: Critical severity phpBB phpbb vulnerability
Published May 19, 2010
·Updated
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."
Affected Software
14 affected componentsFixes available
composer/phpbb/phpbb<3.0.5
3.0.5
phpBB phpbb<=3.0.4
phpBB phpbb=3.0.0
phpBB phpbb=3.0.0-rc1
phpBB phpbb=3.0.0-rc2
phpBB phpbb=3.0.0-rc3
phpBB phpbb=3.0.0-rc4
phpBB phpbb=3.0.0-rc5
phpBB phpbb=3.0.0-rc6
phpBB phpbb=3.0.0-rc7
phpBB phpbb=3.0.0-rc8
phpBB phpbb=3.0.1
phpBB phpbb=3.0.2
phpBB phpbb=3.0.3
Event History
May 19, 2010
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:30 PM
DescriptionSeverityAffected Software
May 17, 2022
Advisory Published
via GitHub·05:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-1630?
The severity of CVE-2010-1630 is currently unspecified due to unknown impact and attack vectors.
2
How do I fix CVE-2010-1630?
To address CVE-2010-1630, you should upgrade to phpBB version 3.0.5 or later.
3
What versions of phpBB are affected by CVE-2010-1630?
CVE-2010-1630 affects all versions of phpBB prior to 3.0.5, including 3.0.0 up to 3.0.4.
4
What does CVE-2010-1630 relate to in phpBB?
CVE-2010-1630 is related to the use of a 'forum id' in posting.php and concerns global announcements.
5
Can CVE-2010-1630 be exploited remotely?
The specifics of the attack vectors are unknown, but vulnerabilities in phpBB generally have the potential for remote exploitation.