Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-25685

phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.0%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2019-25685
  • Phpbb » Phpbb » Version: N/A
    cpe:2.3:a:phpbb:phpbb:-
  • Phpbb » Phpbb » Version: 1.4.0
    cpe:2.3:a:phpbb:phpbb:1.4.0
  • Phpbb » Phpbb » Version: 3.0.0
    cpe:2.3:a:phpbb:phpbb:3.0.0
  • Phpbb » Phpbb » Version: 3.0.1
    cpe:2.3:a:phpbb:phpbb:3.0.1
  • Phpbb » Phpbb » Version: 3.0.10
    cpe:2.3:a:phpbb:phpbb:3.0.10
  • Phpbb » Phpbb » Version: 3.0.11
    cpe:2.3:a:phpbb:phpbb:3.0.11
  • Phpbb » Phpbb » Version: 3.0.12
    cpe:2.3:a:phpbb:phpbb:3.0.12
  • Phpbb » Phpbb » Version: 3.0.13
    cpe:2.3:a:phpbb:phpbb:3.0.13
  • Phpbb » Phpbb » Version: 3.0.2
    cpe:2.3:a:phpbb:phpbb:3.0.2
  • Phpbb » Phpbb » Version: 3.0.3
    cpe:2.3:a:phpbb:phpbb:3.0.3
  • Phpbb » Phpbb » Version: 3.0.4
    cpe:2.3:a:phpbb:phpbb:3.0.4
  • Phpbb » Phpbb » Version: 3.0.5
    cpe:2.3:a:phpbb:phpbb:3.0.5
  • Phpbb » Phpbb » Version: 3.0.6
    cpe:2.3:a:phpbb:phpbb:3.0.6
  • Phpbb » Phpbb » Version: 3.0.7
    cpe:2.3:a:phpbb:phpbb:3.0.7
  • Phpbb » Phpbb » Version: 3.0.8
    cpe:2.3:a:phpbb:phpbb:3.0.8
  • Phpbb » Phpbb » Version: 3.0.9
    cpe:2.3:a:phpbb:phpbb:3.0.9
  • Phpbb » Phpbb » Version: 3.1.0
    cpe:2.3:a:phpbb:phpbb:3.1.0
  • Phpbb » Phpbb » Version: 3.1.1
    cpe:2.3:a:phpbb:phpbb:3.1.1
  • Phpbb » Phpbb » Version: 3.1.10
    cpe:2.3:a:phpbb:phpbb:3.1.10
  • Phpbb » Phpbb » Version: 3.1.11
    cpe:2.3:a:phpbb:phpbb:3.1.11
  • Phpbb » Phpbb » Version: 3.1.2
    cpe:2.3:a:phpbb:phpbb:3.1.2
  • Phpbb » Phpbb » Version: 3.1.3
    cpe:2.3:a:phpbb:phpbb:3.1.3
  • Phpbb » Phpbb » Version: 3.1.4
    cpe:2.3:a:phpbb:phpbb:3.1.4
  • Phpbb » Phpbb » Version: 3.1.5
    cpe:2.3:a:phpbb:phpbb:3.1.5
  • Phpbb » Phpbb » Version: 3.1.6
    cpe:2.3:a:phpbb:phpbb:3.1.6
  • Phpbb » Phpbb » Version: 3.1.7
    cpe:2.3:a:phpbb:phpbb:3.1.7
  • Phpbb » Phpbb » Version: 3.1.8
    cpe:2.3:a:phpbb:phpbb:3.1.8
  • Phpbb » Phpbb » Version: 3.1.9
    cpe:2.3:a:phpbb:phpbb:3.1.9
  • Phpbb » Phpbb » Version: 3.2.0
    cpe:2.3:a:phpbb:phpbb:3.2.0
  • Phpbb » Phpbb » Version: 3.2.1
    cpe:2.3:a:phpbb:phpbb:3.2.1
  • Phpbb » Phpbb » Version: 3.2.2
    cpe:2.3:a:phpbb:phpbb:3.2.2
  • Phpbb » Phpbb » Version: 3.2.3
    cpe:2.3:a:phpbb:phpbb:3.2.3


Contact Us

Shodan ® - All rights reserved