Vulnerabilities
Vulnerable Software
Phpbb:  Security Vulnerabilities
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.
CVSS Score
7.5
EPSS Score
0.003
Published
2002-12-31
phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.
CVSS Score
5.0
EPSS Score
0.003
Published
2002-12-31
phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.
CVSS Score
5.0
EPSS Score
0.006
Published
2002-12-31
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
CVSS Score
8.8
EPSS Score
0.012
Published
2001-07-31


Contact Us

Shodan ® - All rights reserved