CVE-2002-0473Group Phpbb vulnerability

2 documents2 sources
Severity
10.0CRITICALNVD
EPSS
16.9%
top 5.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateApr 30

Description

db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDphpbb_group/phpbb4 versions+3

Patches

🔴Vulnerability Details

1
GHSA
GHSA-8xxh-294r-qp2g: db2022-04-30