CVE-2004-1315

v

iewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpbb_group:phpbb:*:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.6c:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.6d:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.7a:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.8a:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0_beta1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0_rc1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0_rc2:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0_rc3:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:2.0_rc4:*:*:*:*:*:*:*

History

20 Nov 2024, 23:50

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=110029415208724&w=2 - () http://marc.info/?l=bugtraq&m=110029415208724&w=2 -
References () http://marc.info/?l=bugtraq&m=110365752909029&w=2 - () http://marc.info/?l=bugtraq&m=110365752909029&w=2 -
References () http://marc.info/?t=110079440800004&r=1&w=2 - () http://marc.info/?t=110079440800004&r=1&w=2 -
References () http://secunia.com/advisories/13239/ - Patch, Vendor Advisory () http://secunia.com/advisories/13239/ - Patch, Vendor Advisory
References () http://www.kb.cert.org/vuls/id/497400 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/497400 - Patch, Third Party Advisory, US Government Resource
References () http://www.phpbb.com/phpBB/viewtopic.php?t=240513 - Vendor Advisory () http://www.phpbb.com/phpBB/viewtopic.php?t=240513 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/385208 - () http://www.securityfocus.com/archive/1/385208 -
References () http://www.securityfocus.com/bid/10701 - () http://www.securityfocus.com/bid/10701 -
References () http://www.us-cert.gov/cas/techalerts/TA04-356A.html - Patch, Third Party Advisory, US Government Resource () http://www.us-cert.gov/cas/techalerts/TA04-356A.html - Patch, Third Party Advisory, US Government Resource
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18052 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18052 -
References () https://security.gentoo.org/glsa/200411-32 - () https://security.gentoo.org/glsa/200411-32 -

Information

Published : 2004-11-12 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2004-1315

Mitre link : CVE-2004-1315

CVE.ORG link : CVE-2004-1315


JSON object : View

Products Affected