MEDIUM · 5.0

CVE-2002-2346

phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.

Vulnerability Description

phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
PhpbbPhpbb2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-2346?

CVE-2002-2346 is a vulnerability with a CVSS score of 5.0 (MEDIUM). phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.

How severe is CVE-2002-2346?

CVE-2002-2346 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-2346?

Check the references section above for vendor advisories and patch information. Affected products include: Phpbb Phpbb.