CVE-2018-19274
17.11.2018, 13:29
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| phpbb | phpbb | 𝑥 < 3.2.4 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References