phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/423030/100/0/threaded | mailing list |
http://h4cky0u.org/viewtopic.php?t=637 | |
http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt | exploit vendor advisory |
http://securityreason.com/securityalert/368 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24327 | vdb entry |