CVE-2005-3415: High severity Phpbb Group Phpbb vulnerability
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3415?
CVE-2005-3415 is considered a medium severity vulnerability as it allows remote attackers to bypass security controls.
How do I fix CVE-2005-3415?
To fix CVE-2005-3415, upgrade to phpBB version 2.0.18 or later where this vulnerability has been addressed.
What versions are affected by CVE-2005-3415?
CVE-2005-3415 affects phpBB versions 2.0.1 through 2.0.17.
What type of attack can CVE-2005-3415 facilitate?
CVE-2005-3415 can facilitate an attack where remote attackers can manipulate global variables leading to potential data exposure.
Is CVE-2005-3415 reversible?
Once a system is exploited via CVE-2005-3415, reversing the effects requires restoring from backup or applying security patches.