feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.
References
Configurations
Information
Published : 2010-05-19 15:30
Updated : 2010-05-19 21:00
NVD link : CVE-2010-1627
Mitre link : CVE-2010-1627
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
phpbb
- phpbb