Total vulnerabilities in the database
phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.
CVSS v2:
No CWE or OWASP classifications available.