6.1

CVE-2015-3880

Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phpbb ≫ Phpbb Update rc1 Version <= 3.0.14
Phpbb ≫ Phpbb Version 3.1.0
Phpbb ≫ Phpbb Version 3.1.0 Update a1
Phpbb ≫ Phpbb Version 3.1.0 Update a2
Phpbb ≫ Phpbb Version 3.1.0 Update a3
Phpbb ≫ Phpbb Version 3.1.0 Update b1
Phpbb ≫ Phpbb Version 3.1.0 Update b2
Phpbb ≫ Phpbb Version 3.1.0 Update b3
Phpbb ≫ Phpbb Version 3.1.0 Update b4
Phpbb ≫ Phpbb Version 3.1.0 Update rc1
Phpbb ≫ Phpbb Version 3.1.0 Update rc2
Phpbb ≫ Phpbb Version 3.1.0 Update rc3
Phpbb ≫ Phpbb Version 3.1.0 Update rc4
Phpbb ≫ Phpbb Version 3.1.0 Update rc5
Phpbb ≫ Phpbb Version 3.1.0 Update rc6
Phpbb ≫ Phpbb Version 3.1.1
Phpbb ≫ Phpbb Version 3.1.2
Phpbb ≫ Phpbb Version 3.1.2 Update rc1
Phpbb ≫ Phpbb Version 3.1.3
Phpbb ≫ Phpbb Version 3.1.3 Update rc1
Phpbb ≫ Phpbb Version 3.1.3 Update rc2
Phpbb ≫ Phpbb Version 3.1.4 Update rc1
Phpbb ≫ Phpbb Version 3.1.4 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.05% 0.787
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

http://www.openwall.com/lists/oss-security/2015/05/12/10
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/74592
Third Party Advisory
VDB Entry
https://github.com/phpbb/phpbb/commit/1a3350619f428d9d69d196c52128727e27ef2f04
Patch
Third Party Advisory
https://wiki.phpbb.com/Release_Highlights/3.0.14
Third Party Advisory
https://wiki.phpbb.com/Release_Highlights/3.1.4
Third Party Advisory
https://www.phpbb.com/community/viewtopic.php?f=14&t=2313941
Vendor Advisory