Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-1315 | First vendor Publication | 2004-11-12 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1315 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2010-05-05 | Wormable Remote Code Execution in PHP-Nuke 7.0/8.1/8.1.35 |
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200411-32 (phpBB) File : nvt/glsa_200411_32.nasl |
2008-09-04 | Name : FreeBSD Ports: phpbb File : nvt/freebsd_phpbb6.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
11962 | phpBB username Handling SQL Injection phpBB contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the hightlight variable in the viewtopic.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries. |
11961 | phpBB username Handling XSS phpBB contains a flaw that allows a remote cross site scripting attack. The flaw exists because the application does not validate user input upon submission to the username handling routines. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
11719 | phpBB viewtopic.php highlight Parameter SQL Injection phpBB contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'highlight' parameter in the 'viewtopic.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries. |
Snort® IPS/IDS
Date | Description |
---|---|
2015-03-10 | phpBB viewtopic double URL encoding attempt RuleID : 33294 - Revision : 2 - Type : SERVER-WEBAPP |
2015-03-10 | phpBB viewtopic double URL encoding attempt RuleID : 33293 - Revision : 3 - Type : SERVER-WEBAPP |
2014-01-10 | phpBB viewtopic double URL encoding attempt RuleID : 12610 - Revision : 9 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-07-13 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_e3cf89f053da11d992b7ceadd4ac2edd.nasl - Type : ACT_GATHER_INFO |
2005-01-18 | Name : Arbitrary code may be run on the remote server. File : phpbb_viewtopic_script_injection.nasl - Type : ACT_GATHER_INFO |
2004-11-24 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200411-32.nasl - Type : ACT_GATHER_INFO |
2004-11-22 | Name : A remote web application is vulnerable to SQL injection. File : phpbb_login_form_sql.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:53 |
|
2024-11-28 12:06:19 |
|
2021-05-04 12:02:29 |
|
2021-04-22 01:02:40 |
|
2020-05-23 13:16:45 |
|
2020-05-23 00:15:59 |
|
2017-07-11 12:01:35 |
|
2016-12-20 09:24:43 |
|
2016-10-18 12:01:25 |
|
2016-04-26 12:57:58 |
|
2015-03-10 21:24:06 |
|
2014-02-17 10:28:40 |
|
2014-01-19 21:22:22 |
|
2013-05-11 11:44:43 |
|