Description
phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-2221 | phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T17:43:28.582Z
Reserved: 2006-05-05T00:00:00.000Z
Link: CVE-2006-2220
No data.
Status : Deferred
Published: 2007-02-08T17:28:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2006-2220
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD