← Vulnerability feed

Vulnerability record · CVE-2004-1535 · published 31 December 2004

CVE-2004-1535: Phpbb group phpbb vulnerability

Phpbb Group · Phpbb

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

7.5 CVSS 2.0 High EPSS 6.3% · top 6.6%
7.5CVSS 2.0 base score
6.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1535 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-1695Phpbb group phpbb vulnerabilityPHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U…EPSS 1.9%10.0CVE-2006-6839Phpbb group phpbb vulnerabilityUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."EPSS 1.6%10.0CVE-2006-6840Phpbb group phpbb vulnerabilityUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."EPSS 1.6%10.0CVE-2006-6841Phpbb group phpbb vulnerabilityCertain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.EPSS 1.6%10.0CVE-2002-1537Phpbb group phpbb vulnerabilityadmin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields s…EPSS 2.5%10.0CVE-2002-2176Phpbb group phpbb vulnerabilitySQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profil…EPSS 3.3%10.0CVE-2002-0473Phpbb group phpbb vulnerabilitydb.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path param…EPSS 5.3%7.5CVE-2006-5435Phpbb group phpbb vulnerabilityPHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2004-1535), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.