← All CVEs

CVE-2005-1193

high · 7.5

The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.

7.5
CVSS
16.4%
EPSS (exploit prob.)
97th
EPSS percentile
2005-05-16
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
phpbb_groupphpbb2.0.0
phpbb_groupphpbb2.0.1
phpbb_groupphpbb2.0.2
phpbb_groupphpbb2.0.3
phpbb_groupphpbb2.0.4
phpbb_groupphpbb2.0.5
phpbb_groupphpbb2.0.6
phpbb_groupphpbb2.0.6c
phpbb_groupphpbb2.0.6d
phpbb_groupphpbb2.0.7
phpbb_groupphpbb2.0.7a
phpbb_groupphpbb2.0.8
phpbb_groupphpbb2.0.8a
phpbb_groupphpbb2.0.9
phpbb_groupphpbb2.0.10
phpbb_groupphpbb2.0.11
phpbb_groupphpbb2.0.12
phpbb_groupphpbb2.0.13
phpbb_groupphpbb2.0.14
phpbb_groupphpbb2.0_beta1
phpbb_groupphpbb2.0_rc1
phpbb_groupphpbb2.0_rc2
phpbb_groupphpbb2.0_rc3
phpbb_groupphpbb2.0_rc4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-1193