phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/10323.php | vdb entry |
http://online.securityfocus.com/archive/1/294560 | mailing list |
http://www.securityfocus.com/bid/5923 | vdb entry |