A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpbb | Phpbb | * | 3.2.10 (excluding) |
Phpbb | Phpbb | 3.3.0 (including) | 3.3.1 (excluding) |
Phpbb3 | Ubuntu | esm-apps/xenial | * |
Phpbb3 | Ubuntu | esm-infra-legacy/trusty | * |
Phpbb3 | Ubuntu | trusty | * |
Phpbb3 | Ubuntu | trusty/esm | * |
Phpbb3 | Ubuntu | xenial | * |