← Vulnerability feed

Vulnerability record · CVE-2005-2086 · published 5 July 2005

CVE-2005-2086: phpBB viewtopic.php remote file inclusion allows PHP code execution

Phpbb Group · Phpbb

phpBB 2.0.15 and earlier contains a remote file inclusion flaw in viewtopic.php that lets an attacker pull in and execute arbitrary PHP code. Because the vulnerable component is a core forum script reachable by unauthenticated visitors, any exposed board is at risk of full compromise.

7.5 CVSS 2.0 High EPSS 85% · top 0.3%
7.5CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution in a widely deployed forum script with a very high EPSS score, though the product is long end-of-life and no KEV listing exists.

What it is

phpBB 2.0.15 and earlier contains a remote file inclusion flaw in viewtopic.php that lets an attacker pull in and execute arbitrary PHP code. Because the vulnerable component is a core forum script reachable by unauthenticated visitors, any exposed board is at risk of full compromise.

Impact

An attacker can execute arbitrary PHP code on the server, leading to web shell placement, data theft, or complete takeover of the phpBB host. The CVSS 2.0 vector rates confidentiality, integrity, and availability impact as partial.

Attack surface

Reached over the network through viewtopic.php; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any internet-facing phpBB 2.0.15 or earlier installation is directly exposed.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.85366 (99.7th percentile), indicating a very high modeled likelihood of exploitation. A vendor patch reference is present, and no public exploit tag is given in the record.

What to do

  • Upgrade phpBB to a version later than 2.0.15, applying the vendor patch referenced in the advisory.
  • If immediate upgrade is impossible, restrict or block access to viewtopic.php and disable remote file inclusion (allow_url_include/allow_url_fopen) in PHP configuration.
  • Place the forum behind a WAF or reverse proxy that filters file-inclusion style parameters targeting viewtopic.php.
  • Remove write permissions from web-accessible directories and audit the host for dropped PHP webshells.
  • Retire or isolate end-of-life phpBB 2.x installations that cannot be patched.

Detection

  • Search web and PHP logs for requests to viewtopic.php containing remote URL values or path traversal in parameters.
  • Monitor for unexpected outbound HTTP connections originating from the web server process.
  • Scan the webroot for newly created or modified PHP files, especially in upload or cache directories.
  • Alert on PHP errors or includes referencing external hosts in server error logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2086 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-1695Phpbb group phpbb vulnerabilityPHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U…EPSS 1.9%10.0CVE-2006-6839Phpbb group phpbb vulnerabilityUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."EPSS 1.6%10.0CVE-2006-6840Phpbb group phpbb vulnerabilityUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."EPSS 1.6%10.0CVE-2006-6841Phpbb group phpbb vulnerabilityCertain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.EPSS 1.6%10.0CVE-2002-1537Phpbb group phpbb vulnerabilityadmin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields s…EPSS 2.5%10.0CVE-2002-2176Phpbb group phpbb vulnerabilitySQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profil…EPSS 3.3%10.0CVE-2002-0473Phpbb group phpbb vulnerabilitydb.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path param…EPSS 5.3%7.5CVE-2006-5435Phpbb group phpbb vulnerabilityPHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2005-2086), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.