PT-2005-4215 · Phpbb · Phpbb
Stefan Esser
·
Published
2005-11-01
·
Updated
2016-10-18
·
CVE-2005-3419
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpBB version 2.0.17
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
signature bbcode uid parameter in the usercp register.php file, which is not properly initialized.Recommendations
For phpBB version 2.0.17, consider restricting access to the usercp register.php file until a proper fix is applied, and ensure that all parameters, including
signature bbcode uid, are properly sanitized to prevent SQL injection attacks.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpbb