First published: Fri Dec 31 2004(Updated: )
PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb | =2.0.5 | |
Phpbb Group Phpbb | =rc1 | |
Phpbb Group Phpbb | =2.0.8 | |
Phpbb Group Phpbb | =2.0.1 | |
Phpbb Group Phpbb | =2.0.3 | |
Phpbb Group Phpbb | =2.0.4 | |
Phpbb Group Phpbb | =rc4 | |
Phpbb Group Phpbb | =2.0.9 | |
Phpbb Group Phpbb | =2.0.7 | |
Phpbb Group Phpbb | =2.0.2 | |
Phpbb Group Phpbb | =2.0.10 | |
Phpbb Group Phpbb | =rc3 | |
Phpbb Group Phpbb | =rc2 | |
Phpbb Group Phpbb | =2.0.6 | |
Phpbb Group Phpbb | =2.0.0 | |
Phpbb Group Phpbb | =rc1_pre |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1535 is considered a high-severity vulnerability due to its capability to allow remote code execution.
To fix CVE-2004-1535, it is essential to upgrade to a patched version of phpBB that addresses this vulnerability.
CVE-2004-1535 affects phpBB versions 2.0.0 through 2.0.10 and various release candidates.
Yes, CVE-2004-1535 can lead to data breaches as it allows attackers to execute arbitrary PHP code on the server.
CVE-2004-1535 is a significant risk for phpBB users who are still operating on the vulnerable versions and have not applied security updates.