Release date:2010-11-22
Updated on:2010-11-25
Affected Systems:
PhpBB
Description:
PhpBB is a world-renowned open-source announcement board system.
PhpBB does not properly filter user input data. Remote attackers can insert malicious data in submitted requests, resulting in injection and execution of malicious script code.
Attackers can exploit this vulnerability to execute arbitrary script code in the affected site's browser as a trusted user, steal cookie-based authentication certificates, control the site appearance or launch other attacks. Versions earlier than phpBB 3.0.8 are vulnerable to attacks.
<**>
Suggestion:Vendor patch:
PhpBB
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpbb.com/support/documents.php? Mode = changelog & version = 3 # v307-PL1