Back

CVE-2005-1378

SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.

Published: May 3, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
oxpus phpbb_personal_notes_module *

GitHub Security Advisory GHSA-2pf6-f7gf-h6vx

SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.65%

Top 25% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub