Логотип exploitDog
bind:CVE-2004-1315
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2004-1315

Количество 3

Количество 3

nvd логотип

CVE-2004-1315

почти 21 год назад

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

CVSS2: 7.5
EPSS: Высокий
debian логотип

CVE-2004-1315

почти 21 год назад

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the hi ...

CVSS2: 7.5
EPSS: Высокий
github логотип

GHSA-x5j2-7752-gm38

больше 3 лет назад

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1315

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

CVSS2: 7.5
86%
Высокий
почти 21 год назад
debian логотип
CVE-2004-1315

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the hi ...

CVSS2: 7.5
86%
Высокий
почти 21 год назад
github логотип
GHSA-x5j2-7752-gm38

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

86%
Высокий
больше 3 лет назад

Уязвимостей на страницу