Back

CVE-2005-3328

PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter.

Published: Oct 27, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
punbb punbb 1.1.2
punbb punbb 1.1.3
punbb punbb 1.1.4
punbb punbb 1.1.5

GitHub Security Advisory GHSA-3fqp-83fp-r6mv

PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.58%

Top 16% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub