Security Advisory

CVE-2003-1373

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-10-17 01:00:00
Last updated 2024-08-08 02:28:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.