MEDIUM
phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database
Published Jan 27, 2006
5.0
MEDIUMCVSS 2.0
EPSS 5.09%
Description
phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
Affected products
No data.
OR
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.6c
- 2.0.6d
- 2.0.7
- 2.0.7a
- 2.0.8
- 2.0.8a
- 2.0.9
- 2.0.10
- 2.0.11
- 2.0.12
- 2.0.13
- 2.0.14
- 2.0.15
- 2.0.16
- 2.0.17
- 2.0.18
- 2.0.19
- 2.0_beta1
- 2.0_rc1
- 2.0_rc2
- 2.0_rc3
- 2.0_rc4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (5)
- http://h4cky0u.org/viewtopic.php?t=637 x_refsource_MISC
- http://securityreason.com/securityalert/368 third-party-advisoryx_refsource_SREASON
- http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt x_refsource_MISCExploitVendor Advisory
- http://www.securityfocus.com/archive/1/423030/100/0/threaded mailing-listx_refsource_BUGTRAQ
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24327 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://h4cky0u.org/viewtopic.php?t=637 | x_refsource_MISC | |
| http://securityreason.com/securityalert/368 | third-party-advisoryx_refsource_SREASON | |
| http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt | x_refsource_MISCExploitVendor Advisory | |
| http://www.securityfocus.com/archive/1/423030/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/24327 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 27, 2006
Updated Aug 7, 2024
Reserved Jan 26, 2006
Link CVE-2006-0450
CISA Vulnrichment
Updated n/a