Title : phpBB Administrator Session Handling Critical Security Update VUPEN ID : VUPEN/ADV-2005-0212 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-02-28
Technical Description
Two vulnerabilities were reported in phpBB, which may be exploited by attackers to determine the installation path or bypass certain security features. The first problem resides in the "autologinid" (includes/sessions.php) variable and could be exploited by malicious users to gain administrator rights. The second flaw resides in the "viewtopic.php" script, and could be exploited to disclose the webroot path.