CVE-2004-1315: High severity Phpbb Group Phpbb vulnerability
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1315?
CVE-2004-1315 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2004-1315?
To fix CVE-2004-1315, upgrade phpBB to version 2.0.11 or later.
What are the affected versions in CVE-2004-1315?
CVE-2004-1315 affects phpBB versions 2.0.0 to 2.0.10 and various 1.x versions.
Can CVE-2004-1315 be exploited remotely?
Yes, CVE-2004-1315 can be exploited remotely by attackers through specially crafted HTTP requests.
What is the impact of CVE-2004-1315?
The impact of CVE-2004-1315 allows an attacker to execute arbitrary PHP code on the server.