Short Name |
HTTP:PHP:PHPBB:LANG-EXEC |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
phpBB Language Preference Arbitrary File Execution |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a vulnerability in the prefs.php script that ships with phpBB 1.4. Attackers can send a maliciously crafted request to prefs.php to execute files on the host as a PHP script.
A SQL injection vulnerability has been reported in phpBB2. phpBB2, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries. This may result in unauthorized operations being performed on the underlying database. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.