Vulnerabilities
Vulnerable Software
Phpbb:  >> Phpbb  >> 2.0.23  Security Vulnerabilities
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.
CVSS Score
6.8
EPSS Score
0.004
Published
2009-09-01


Contact Us

Shodan ® - All rights reserved