vendor:
PHPBB2
by:
Unknown
7.5
CVSS
HIGH
Administrative Access
CWE
Product Name: PHPBB2
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
PHPBB2 Administrative Access Vulnerability
The vulnerability in PHPBB2 allows attackers to gain administrative access to the application by bypassing access validation. Attackers can modify the user level and user number parameters in the form to gain administrative privileges.
Mitigation:
Apply the latest patches and updates for PHPBB2. Restrict access to the administrative interface.