CVE
- Id
- 14621
- CVE No.
- CVE-2005-3415
- Status
- Candidate
- Description
- phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable.
- Phase
- Assigned (20051101)
- Votes
- None (candidate not yet proposed)
- Comments