Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpBB Avatar_Path PHP代码执行漏洞
Vulnerability Description
phpBB 2.0.21未适当处理以%00结尾的路径名称,远程认证的管理用户可以上传任意文件,如使用以.php%00结尾的 avatar_path参数查询admin/admin_board.php所示。
CVSS Information
N/A
Vulnerability Type
N/A