VulnerabilityModified
CVE-2002-0473
db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.
HIGH 10.0EPSS 5.27%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.27% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- phpbb group/phpbb
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-03/0221.html
- http://archives.neohapsis.com/archives/bugtraq/2002-03/0229.html
- http://online.securityfocus.com/archive/82/262600Vendor Advisory
- http://phpbb.sourceforge.net/phpBB2/viewtopic.php?t=9483
- http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.1.zip
- http://www.iss.net/security_center/static/8476.phpVendor Advisory
- http://www.osvdb.org/4268
- http://www.securityfocus.com/bid/4380Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-03/0221.html
- http://archives.neohapsis.com/archives/bugtraq/2002-03/0229.html
- http://online.securityfocus.com/archive/82/262600Vendor Advisory
- http://phpbb.sourceforge.net/phpBB2/viewtopic.php?t=9483
- http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.1.zip
- http://www.iss.net/security_center/static/8476.phpVendor Advisory
- http://www.osvdb.org/4268
- http://www.securityfocus.com/bid/4380Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.