HIGH · 7.5

CVE-2005-3417

phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associa...

Vulnerability Description

phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Phpbb GroupPhpbb2.0.0

References

FAQ

What is CVE-2005-3417?

CVE-2005-3417 is a vulnerability with a CVSS score of 7.5 (HIGH). phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associa...

How severe is CVE-2005-3417?

CVE-2005-3417 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3417?

Check the references section above for vendor advisories and patch information. Affected products include: Phpbb Group Phpbb.