peter bassill · operator
$ cve CVE-2005-1196 JSON

CVE-2005-1196 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.98% — more likely to be exploited than 80% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
phpbb groupphpbb

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD