← Back

CVE-2002-1707

nvd nist
Published: Dec 31, 2002Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.

Affected (6)

Products: Phpbb Group: Phpbb
1 product
Phpbb
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Phpbb Group
Version 2.0.0
Version 2.0.1
Version 2.0_rc1
Version 2.0_rc2
Version 2.0_rc3
Version 2.0_rc4

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.