Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpBB admin/admin_disallow.php 远程攻击漏洞
Vulnerability Description
phpBB 2.0.18中的admin/admin_disallow.php使得远程攻击者可以通过直接请求一个非空的setmodules参数获取安装路径,这种作法可造成一个无效的append_sid函数调用,从而将路径暴露在错误信息中。
CVSS Information
N/A
Vulnerability Type
N/A