CVE-2003-1373
Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.
Scoring
- CVSS base score
- 0.01
- EPSS probability
- 0.15%
- Published
- 2007-10-17
- Last modified
- 2026-03-16
Affected products
- n/a n/a