Back

CVE-2003-1244

SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (3)

Vendor Product Version
phpbb_group phpbb 2.0.0
phpbb_group phpbb 2.0.1
phpbb_group phpbb 2.0.2

GitHub Security Advisory GHSA-jwcv-v5fq-fx8v

SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.19%

Top 35% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub