Don't know if it applies... --------------------------------------- Version(s): 1.1 Description: A vulnerability was reported in the 'File Upload Script' phpBB MOD. A remote user can upload files with arbitrary content and filename extensions. The 'up.php' script does not restrict filename extensions or file contents. A remote user can upload an arbitrary file with a '.php' file extension. Then, the remote user can invoke the uploaded file to execute arbitrary PHP code and operating system commands on the target system with the privileges of the target web service. Impact: A remote user can upload arbitrary PHP code to the target system and then execute the code with the privileges of the target web service. Solution: No solution was available at the time of this entry.
This mod is not in the phpBB shipped in portage.