Description
|
|
Multiple vulnerabilities were identified in PunBB, which may be exploited by attackers to gain knowledge of sensitive information or conduct cross site scripting and spoofing attacks.
The first flaw is due to an input validation error in the avatar upload feature that does not properly handle specially crafted images, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.
The second issue is due to an input validation error when processing a specially crafted "HTTP_X_FORWARDED_FOR" parameter, which could be exploited by malicious users to conduct IP spoofing attacks.
The third flaw is due to an unspecified error in the "unregister_globals()" function, which could be exploited by attackers to disclose sensitive information.
|