vendor:
PhpBB
by:
rgod
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: PhpBB
Affected Version From: PhpBB 3
Affected Version To: PhpBB 3 (specific versions not provided)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
PhpBB 3 memberlist.php/’ip’ argument SQL injection / admin credentials disclosure
This exploit allows an attacker to disclose admin credentials through an SQL injection vulnerability in the 'ip' argument of the memberlist.php file in PhpBB 3. It works regardless of php.ini settings and requires a global moderator account with 'simple moderator' role.
Mitigation:
Patch or update to a version of PhpBB that does not contain this vulnerability.