PT-2005-2787 · Zeroboard · Zeroboard
Published
2005-06-01
·
Updated
2008-09-05
·
CVE-2005-1820
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zeroboard versions 4.1pl2 through 4.1pl5
Description
The issue allows remote attackers to execute arbitrary PHP code due to improper quoting when using the
preg replace function.Recommendations
For Zeroboard versions 4.1pl2 through 4.1pl5, update to a version that properly quotes input to prevent code execution.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zeroboard