Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPBB全局变量取消注册绕过保护机制漏洞
Vulnerability Description
phpBB 2是一个论坛软件,使用PHP语言开发的并开放其原始码。 phpBB 2.0.17和更早版本可让远程攻击者通过将GET/POST/COOKIE (GPC)变量和GLOBALS[]变量同时设为相同名称来绕过可取消注册全局变量的保护机制,这会使phpBB取消设置GLOBALS[]变量,而非GPC变量。
CVSS Information
N/A
Vulnerability Type
N/A