7.5
CVSSv2

CVE-2005-3415

Published: 01/11/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

phpBB 2.0.17 and previous versions allows remote malicious users to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.16

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0 rc2

phpbb group phpbb 2.0 rc1

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.9

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0.15

phpbb group phpbb 2.0 rc4

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0.17

phpbb group phpbb 2.0 rc3

phpbb group phpbb 2.0 beta1

Vendor Advisories

Several vulnerabilities have been discovered in phpBB, a fully featured and skinnable flat webforum The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3310 Multiple interpretation errors allow remote authenticated users to inject arbitrary web script when remote avatars and avatar uploading ar ...