PT-2004-2840 · Phpbb · Phpbb

Dariusz Kolasinski

+1

·

Published

2004-04-19

·

Updated

2017-07-11

·

CVE-2004-1943

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpBB version 1.8
Description The issue allows remote attackers to execute arbitrary PHP code via the phpbb root path parameter in the album portal.php file.
Recommendations For version 1.8, update the phpBB software to a version that fixes this issue, ensuring the phpbb root path parameter is properly sanitized to prevent remote file inclusion attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1943

Affected Products

Phpbb