Vulnerability record · CVE-2005-2086 · published 5 July 2005
CVE-2005-2086: phpBB viewtopic.php remote file inclusion allows PHP code execution
Phpbb Group · Phpbb
phpBB 2.0.15 and earlier contains a remote file inclusion flaw in viewtopic.php that lets an attacker pull in and execute arbitrary PHP code. Because the vulnerable component is a core forum script reachable by unauthenticated visitors, any exposed board is at risk of full compromise.
Description
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution in a widely deployed forum script with a very high EPSS score, though the product is long end-of-life and no KEV listing exists.
What it is
phpBB 2.0.15 and earlier contains a remote file inclusion flaw in viewtopic.php that lets an attacker pull in and execute arbitrary PHP code. Because the vulnerable component is a core forum script reachable by unauthenticated visitors, any exposed board is at risk of full compromise.
Impact
An attacker can execute arbitrary PHP code on the server, leading to web shell placement, data theft, or complete takeover of the phpBB host. The CVSS 2.0 vector rates confidentiality, integrity, and availability impact as partial.
Attack surface
Reached over the network through viewtopic.php; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any internet-facing phpBB 2.0.15 or earlier installation is directly exposed.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.85366 (99.7th percentile), indicating a very high modeled likelihood of exploitation. A vendor patch reference is present, and no public exploit tag is given in the record.
What to do
- Upgrade phpBB to a version later than 2.0.15, applying the vendor patch referenced in the advisory.
- If immediate upgrade is impossible, restrict or block access to viewtopic.php and disable remote file inclusion (allow_url_include/allow_url_fopen) in PHP configuration.
- Place the forum behind a WAF or reverse proxy that filters file-inclusion style parameters targeting viewtopic.php.
- Remove write permissions from web-accessible directories and audit the host for dropped PHP webshells.
- Retire or isolate end-of-life phpBB 2.x installations that cannot be patched.
Detection
- Search web and PHP logs for requests to viewtopic.php containing remote URL values or path traversal in parameters.
- Monitor for unexpected outbound HTTP connections originating from the web server process.
- Scan the webroot for newly created or modified PHP files, especially in upload or cache directories.
- Alert on PHP errors or includes referencing external hosts in server error logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2086 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2086), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.