Логотип exploitDog
bind:CVE-2004-1315
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2004-1315

Количество 3

Количество 3

nvd логотип

CVE-2004-1315

около 21 года назад

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

CVSS2: 7.5
EPSS: Высокий
debian логотип

CVE-2004-1315

около 21 года назад

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the hi ...

CVSS2: 7.5
EPSS: Высокий
github логотип

GHSA-x5j2-7752-gm38

почти 4 года назад

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1315

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

CVSS2: 7.5
86%
Высокий
около 21 года назад
debian логотип
CVE-2004-1315

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the hi ...

CVSS2: 7.5
86%
Высокий
около 21 года назад
github логотип
GHSA-x5j2-7752-gm38

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

86%
Высокий
почти 4 года назад

Уязвимостей на страницу