CVE-2006-4758

Priority
Description
phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows
remote authenticated administrative users to upload arbitrary files, as
demonstrated by a query to admin/admin_board.php with an avatar_path
parameter ending in .php%00.
Package
Upstream:needs-triage
Patches:
Vendor:http://www.debian.org/security/2008/dsa-1488
More Information

Updated: 2019-03-19 11:40:02 UTC (commit 15472795df7e9de45b82f2d36b8b419b939f97b2)