Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.
| Software | From | Fixed in |
|---|---|---|
| phpbb_group / phpbb | 1.4.1 | 1.4.1.x |
| phpbb_group / phpbb | 1.4.4 | 1.4.4.x |
| phpbb_group / phpbb | 1.4.2 | 1.4.2.x |
| phpbb_group / phpbb | 1.4.0 | 1.4.0.x |