Back

CVE-2003-1373

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (4)

Vendor Product Version
phpbb_group phpbb 1.4.0
phpbb_group phpbb 1.4.1
phpbb_group phpbb 1.4.2
phpbb_group phpbb 1.4.4

GitHub Security Advisory GHSA-5wg6-v5wg-r8c6

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.27%

Top 33% most likely to be exploited

Threat Score 27.6 / 100

Data Sources

NVD EPSS GitHub