← Back

CVE-2004-1315

nvd nist
Published: Nov 12, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

Affected (29)

Products: Phpbb Group: Phpbb
1 product
Phpbb
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Phpbb Group
All versions
Version 1.0.0
Version 1.0.1
Version 1.2.0
Version 1.2.1
Version 1.4.0
Version 1.4.1
Version 1.4.2
Version 1.4.4
Version 2.0.0
Version 2.0.10
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.6c
Version 2.0.6d
Version 2.0.7
Version 2.0.7a
Version 2.0.8
Version 2.0.8a
Version 2.0.9
Version 2.0_beta1
Version 2.0_rc1
Version 2.0_rc2
Version 2.0_rc3
Version 2.0_rc4

References (22)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.