CVE-2005-4358
Publication date 20 December 2005
Last updated 17 July 2025
Ubuntu priority
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.
Status
Package | Ubuntu Release | Status |
---|---|---|
phpbb2 | 9.10 karmic | Not in release |
9.04 jaunty | Not in release | |
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Not affected
|
|
7.04 feisty |
Not affected
|
|
6.10 edgy |
Not affected
|
|
6.06 LTS dapper | Ignored end of life |