CVE Database
/

CVE-2005-3420

Back to search

CVE-2005-3420

Published: Nov 1, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2005-2250
vdb-entry
x_refsource_VUPEN
DSA-925
vendor-advisory
x_refsource_DEBIAN
17366
third-party-advisory
x_refsource_SECUNIA
130
third-party-advisory
x_refsource_SREASON
18098
third-party-advisory
x_refsource_SECUNIA
20391
vdb-entry
x_refsource_OSVDB
1015121
vdb-entry
x_refsource_SECTRACK
15243
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now