CVE-2004-1315
Last modified
CVE-2004-1315 is a vulnerability of currently unknown severity. viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.. EPSS estimates a 71.90% chance of exploitation in the next 30 days.
Description
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpbb Group | Phpbb | All versions |
| Phpbb Group | Phpbb | 1.0.0 |
| Phpbb Group | Phpbb | 1.0.1 |
| Phpbb Group | Phpbb | 1.2.0 |
| Phpbb Group | Phpbb | 1.2.1 |
| Phpbb Group | Phpbb | 1.4.0 |
| Phpbb Group | Phpbb | 1.4.1 |
| Phpbb Group | Phpbb | 1.4.2 |
| Phpbb Group | Phpbb | 1.4.4 |
| Phpbb Group | Phpbb | 2.0.0 |
| Phpbb Group | Phpbb | 2.0.1 |
| Phpbb Group | Phpbb | 2.0.2 |
| Phpbb Group | Phpbb | 2.0.3 |
| Phpbb Group | Phpbb | 2.0.4 |
| Phpbb Group | Phpbb | 2.0.5 |
| Phpbb Group | Phpbb | 2.0.6 |
| Phpbb Group | Phpbb | 2.0.6c |
| Phpbb Group | Phpbb | 2.0.6d |
| Phpbb Group | Phpbb | 2.0.7 |
| Phpbb Group | Phpbb | 2.0.7a |
| Phpbb Group | Phpbb | 2.0.8 |
| Phpbb Group | Phpbb | 2.0.8a |
| Phpbb Group | Phpbb | 2.0.9 |
| Phpbb Group | Phpbb | 2.0.10 |
| Phpbb Group | Phpbb | 2.0_beta1 |
| Phpbb Group | Phpbb | 2.0_rc1 |
| Phpbb Group | Phpbb | 2.0_rc2 |
| Phpbb Group | Phpbb | 2.0_rc3 |
| Phpbb Group | Phpbb | 2.0_rc4 |
References
- http://secunia.com/advisories/13239/Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/497400Patch, Third Party Advisory, US Government Resource
- http://www.phpbb.com/phpBB/viewtopic.php?t=240513Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-356A.htmlPatch, Third Party Advisory, US Government Resource
- http://secunia.com/advisories/13239/Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/497400Patch, Third Party Advisory, US Government Resource
- http://www.phpbb.com/phpBB/viewtopic.php?t=240513Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-356A.htmlPatch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1315?
How severe is CVE-2004-1315?
How do I fix CVE-2004-1315?
Are you affected by CVE-2004-1315?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
