PT-2005-4215 · Phpbb · Phpbb

Stefan Esser

·

Published

2005-11-01

·

Updated

2016-10-18

·

CVE-2005-3419

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpBB version 2.0.17
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the signature bbcode uid parameter in the usercp register.php file, which is not properly initialized.
Recommendations For phpBB version 2.0.17, consider restricting access to the usercp register.php file until a proper fix is applied, and ensure that all parameters, including signature bbcode uid, are properly sanitized to prevent SQL injection attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3419
DSA-925-1

Affected Products

Phpbb