CVE-2005-4346
Estado: ModificadaMedia (5)—
Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a SQL syntax error message. NOTE: this was originally claimed to be SQL injection, but a cleansing step strips all non-digit characters and leaves an empty permalink argument, which leads to the syntax error.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.30%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://pridels0.blogspot.com/2005/12/phpbb-blog-222-sql-inj-vuln.html
- http://www.osvdb.org/21565
- http://www.outshine.com/forums/viewtopic.php?t=308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23495
- http://pridels0.blogspot.com/2005/12/phpbb-blog-222-sql-inj-vuln.html
- http://www.osvdb.org/21565
- http://www.outshine.com/forums/viewtopic.php?t=308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23495
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-4346",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-12-19T03:47:00.000",
"references": [
{
"url": "http://pridels0.blogspot.com/2005/12/phpbb-blog-222-sql-inj-vuln.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/21565",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.outshine.com/forums/viewtopic.php?t=308",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23495",
"source": "cve@mitre.org"
},
{
"url": "http://pridels0.blogspot.com/2005/12/phpbb-blog-222-sql-inj-vuln.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/21565",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.outshine.com/forums/viewtopic.php?t=308",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23495",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a SQL syntax error message. NOTE: this was originally claimed to be SQL injection, but a cleansing step strips all non-digit characters and leaves an empty permalink argument, which leads to the syntax error."
},
{
"lang": "es",
"value": "Vulnerabilidad de error de sintaxis SQL no válido en blog.php de phpBB Blog 2.2.2 y anteriores permite a atacantes remotos obtener la ruta completa de la aplicación mediante un parámetro \"permalink\" no válido para index.php, lo que filtra la ruta completa en un mensaje de error de sintaxis de SQL. NOTA: Anteriormente se afirmó que esta era una vulnerabilidad de inyección de SQL, pero un paso de limpieza extrae todos los caractéres no dígitos, y deja un argumento \"permalink\" vacío, lo que conduce al error de sintaxis."
}
],
"lastModified": "2026-06-16T22:18:37.697",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:anthony_boyd:phpbb_blog:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1D947CC-28AC-4A30-AED3-A5443815E5C6",
"versionEndIncluding": "2.2.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}