Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-4758
Description:phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.
Test IDs: 1.3.6.1.4.1.25623.1.0.60361   1.3.6.1.4.1.25623.1.0.57463  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-4758
BugTraq ID: 20347
http://www.securityfocus.com/bid/20347
BugTraq ID: 21806
http://www.securityfocus.com/bid/21806
Bugtraq: 20060911 ShAnKaR: multiple PHP application poison NULL byte vulnerability (Google Search)
http://www.securityfocus.com/archive/1/445788/100/0/threaded
Debian Security Information: DSA-1488 (Google Search)
http://www.debian.org/security/2008/dsa-1488
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=489624
http://www.security.nnov.ru/Odocument221.html
http://secunia.com/advisories/22188
http://secunia.com/advisories/28871
XForce ISS Database: phpbb-nullbyte-file-upload(28884)
https://exchange.xforce.ibmcloud.com/vulnerabilities/28884




© 1998-2025 E-Soft Inc. All rights reserved.