Security phpBB 2.0.14
Geplaatst: 20 apr 2005, 09:55
Ik kwam op Security Focus de volgende "vulnerabilities" tegen. Kan iemand me met zekerheid zeggen of deze in versie 2.0.14 allemaal zijn opgelost? Volgens de SF site is het t/m 2.0.13 in ieder geval nog onveilig.
> 69. PHPBB2 Plus GroupCP.PHP Cross-Site Scripting Vulnerability
> BugTraq ID: 13149
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13149
> Summary:
> phpBB2 Plus is affected by a cross-site scripting
> vulnerability. This issue is due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage this issue to have arbitrary script
> code executed in the browser of an unsuspecting user. This
> may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> 70. PHPBB2 Plus Index.PHP Multiple Cross-Site Scripting Vulnerab...
> BugTraq ID: 13150
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13150
> Summary:
> phpBB2 Plus is affected by multiple cross-site scripting
> vulnerabilities. These issues are due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage these issues to have arbitrary
> script code executed in the browser of an unsuspecting user.
> This may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> These issues affect phpBB2 Plus version 1.52 and earlier.
>
> 71. PHPBB2 Plus Portal.PHP Multiple Cross-Site Scripting Vulnera...
> BugTraq ID: 13151
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13151
> Summary:
> phpBB2 Plus is affected by multiple cross-site scripting
> vulnerabilities. These issues are due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage these issues to have arbitrary
> script code executed in the browser of an unsuspecting user.
> This may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> These issues affect phpBB2 Plus version 1.52 and earlier.
>
> 72. PHPBB2 Plus ViewForum.PHP Cross-Site Scripting Vulnerability
> BugTraq ID: 13152
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13152
> Summary:
> phpBB2 Plus is affected by a cross-site scripting
> vulnerability. This issue is due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage this issue to have arbitrary script
> code executed in the browser of an unsuspecting user. This
> may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> 73. PHPBB2 Plus ViewTopic.PHP Cross-Site Scripting Vulnerability
> BugTraq ID: 13153
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13153
> Summary:
> phpBB2 Plus is affected by a cross-site scripting
> vulnerability. This issue is due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage this issue to have arbitrary script
> code executed in the browser of an unsuspecting user. This
> may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
> 69. PHPBB2 Plus GroupCP.PHP Cross-Site Scripting Vulnerability
> BugTraq ID: 13149
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13149
> Summary:
> phpBB2 Plus is affected by a cross-site scripting
> vulnerability. This issue is due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage this issue to have arbitrary script
> code executed in the browser of an unsuspecting user. This
> may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> 70. PHPBB2 Plus Index.PHP Multiple Cross-Site Scripting Vulnerab...
> BugTraq ID: 13150
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13150
> Summary:
> phpBB2 Plus is affected by multiple cross-site scripting
> vulnerabilities. These issues are due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage these issues to have arbitrary
> script code executed in the browser of an unsuspecting user.
> This may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> These issues affect phpBB2 Plus version 1.52 and earlier.
>
> 71. PHPBB2 Plus Portal.PHP Multiple Cross-Site Scripting Vulnera...
> BugTraq ID: 13151
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13151
> Summary:
> phpBB2 Plus is affected by multiple cross-site scripting
> vulnerabilities. These issues are due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage these issues to have arbitrary
> script code executed in the browser of an unsuspecting user.
> This may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> These issues affect phpBB2 Plus version 1.52 and earlier.
>
> 72. PHPBB2 Plus ViewForum.PHP Cross-Site Scripting Vulnerability
> BugTraq ID: 13152
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13152
> Summary:
> phpBB2 Plus is affected by a cross-site scripting
> vulnerability. This issue is due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage this issue to have arbitrary script
> code executed in the browser of an unsuspecting user. This
> may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.
>
> 73. PHPBB2 Plus ViewTopic.PHP Cross-Site Scripting Vulnerability
> BugTraq ID: 13153
> Remote: Yes
> Date Published: Apr 13 2005
> Relevant URL: http://www.securityfocus.com/bid/13153
> Summary:
> phpBB2 Plus is affected by a cross-site scripting
> vulnerability. This issue is due to a failure in the
> application to properly sanitize user-supplied input.
>
> An attacker may leverage this issue to have arbitrary script
> code executed in the browser of an unsuspecting user. This
> may facilitate the theft of cookie-based authentication
> credentials as well as other attacks.