CVE-2005-1196 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.98% — more likely to be exploited than 80% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| phpbb group | phpbb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | phpBB 1.x/2.0.x - Knowledge Base Module 'KB.php' SQL Injection | 2005-04-13 |
References
→ the Explorer · watch your stack · NVD