First published: Wed May 19 2010(Updated: )
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpbb/phpbb | <3.0.5 | 3.0.5 |
phpBB | <=3.0.4 | |
phpBB | =3.0.0 | |
phpBB | =3.0.0-rc1 | |
phpBB | =3.0.0-rc2 | |
phpBB | =3.0.0-rc3 | |
phpBB | =3.0.0-rc4 | |
phpBB | =3.0.0-rc5 | |
phpBB | =3.0.0-rc6 | |
phpBB | =3.0.0-rc7 | |
phpBB | =3.0.0-rc8 | |
phpBB | =3.0.1 | |
phpBB | =3.0.2 | |
phpBB | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-1630 is currently unspecified due to unknown impact and attack vectors.
To address CVE-2010-1630, you should upgrade to phpBB version 3.0.5 or later.
CVE-2010-1630 affects all versions of phpBB prior to 3.0.5, including 3.0.0 up to 3.0.4.
CVE-2010-1630 is related to the use of a 'forum id' in posting.php and concerns global announcements.
The specifics of the attack vectors are unknown, but vulnerabilities in phpBB generally have the potential for remote exploitation.