Back

CVE-2002-1482

SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.

Published: Apr 22, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
phpgb phpgb 1.10
phpgb phpgb 1.20
phpgb phpgb 1.30

GitHub Security Advisory GHSA-g4g9-vhf3-m2x9

SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 3.68%

Top 11% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub