MEDIUM
usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request
Published Aug 30, 2006
5.1
MEDIUMCVSS 2.0
EPSS 4.20%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.