CVE-2005-1196

phpBB Knowledge Base module - SQL Injection via cat Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1196. PoCs published by [email protected].

AI-analyzed exploit summary The provided code is a writeup describing an SQL injection vulnerability in the Knowledge Base Module. It includes a sample exploit URL demonstrating the vulnerability but lacks executable code.

Description

SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25451

The provided code is a writeup describing an SQL injection vulnerability in the Knowledge Base Module. It includes a sample exploit URL demonstrating the vulnerability but lacks executable code.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Knowledge Base Module (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable web application
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111384185116335&w=2

Scores

EPSS 0.0198
EPSS Percentile 78.5%

Details

Status published
Products (1)
phpbb_group/phpbb
Published May 02, 2005
Tracked Since Feb 18, 2026