CVE

Id
14621  
CVE No.
CVE-2005-3415  
Status
Candidate  
Description
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable.  
Phase
Assigned (20051101)  
Votes
None (candidate not yet proposed)  
Comments