CVE-2004-2350

phpBB <2.0.6 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by pokleyzz · phpwebappsphp
https://www.exploit-db.com/exploits/23821

Scores

EPSS 0.0054
EPSS Percentile 67.5%

Details

Status published
Products (19)
phpbb_group/phpbb 1.0.0
phpbb_group/phpbb 1.2.0
phpbb_group/phpbb 1.2.1
phpbb_group/phpbb 1.4.0
phpbb_group/phpbb 1.4.1
phpbb_group/phpbb 1.4.2
phpbb_group/phpbb 1.4.4
phpbb_group/phpbb 2.0.0
phpbb_group/phpbb 2.0.1
phpbb_group/phpbb 2.0.2
... and 9 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026