PT-2006-2880 · Phpbb Limited · Phpbb

Noch22

·

Published

2006-04-20

·

Updated

2018-10-18

·

CVE-2006-1896

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpBB (affected versions not specified)
Description The issue allows remote authenticated users with Administration Panel access to execute arbitrary PHP code. This can be achieved by crafting specific values, such as Font Colour 3, which is associated with the theme[fontcolor3] variable, and/or signature values. The vulnerability might involve the highlight functionality, although the exact nature of the issue, whether it is static code injection, eval injection, or another type, is not clearly specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1896
DSA-1066-1

Affected Products

Phpbb