CVE-2004-1315
EXPLOITEDphpBB 2.x <2.0.11 - RCE
Title source: llmDescription
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by sasan hezarkhani · perlwebappsphp
https://www.exploit-db.com/exploits/24274
References (11)
Scores
EPSS
0.8591
EPSS Percentile
99.4%
Details
VulnCheck KEV
2017-06-20
Status
published
Products (29)
phpbb_group/phpbb
phpbb_group/phpbb
1.0.0
phpbb_group/phpbb
1.0.1
phpbb_group/phpbb
1.2.0
phpbb_group/phpbb
1.2.1
phpbb_group/phpbb
1.4.0
phpbb_group/phpbb
1.4.1
phpbb_group/phpbb
1.4.2
phpbb_group/phpbb
1.4.4
phpbb_group/phpbb
2.0.0
... and 19 more
Published
Nov 12, 2004
Tracked Since
Feb 18, 2026