Back to search
CVE-2018-19274
Published: Nov 17, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.phpbb.com/community/viewtopic.php?f=14&t=2492206
x_refsource_CONFIRM
[debian-lts-announce] 20181124 [SECURITY] [DLA 1593-1] phpbb3 security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now