← All CVEs

CVE-2004-1315

high · 7.5

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

7.5
CVSS
72.1%
EPSS (exploit prob.)
99th
EPSS percentile
2004-11-12
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
phpbb_groupphpbball versions
phpbb_groupphpbb1.0.0
phpbb_groupphpbb1.0.1
phpbb_groupphpbb1.2.0
phpbb_groupphpbb1.2.1
phpbb_groupphpbb1.4.0
phpbb_groupphpbb1.4.1
phpbb_groupphpbb1.4.2
phpbb_groupphpbb1.4.4
phpbb_groupphpbb2.0.0
phpbb_groupphpbb2.0.1
phpbb_groupphpbb2.0.2
phpbb_groupphpbb2.0.3
phpbb_groupphpbb2.0.4
phpbb_groupphpbb2.0.5
phpbb_groupphpbb2.0.6
phpbb_groupphpbb2.0.6c
phpbb_groupphpbb2.0.6d
phpbb_groupphpbb2.0.7
phpbb_groupphpbb2.0.7a
phpbb_groupphpbb2.0.8
phpbb_groupphpbb2.0.8a
phpbb_groupphpbb2.0.9
phpbb_groupphpbb2.0.10
phpbb_groupphpbb2.0_beta1
phpbb_groupphpbb2.0_rc1
phpbb_groupphpbb2.0_rc2
phpbb_groupphpbb2.0_rc3
phpbb_groupphpbb2.0_rc4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1315