Loading
Generated remediation guidance and an executive summary. No account required.
phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables.
Use Phpbb Group vendor hub and Phpbb product page to widen CVE-2005-3417 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-1695, CVE-2006-6841 and CVE-2006-6840 for nearby disclosures in the same product family.