CVE Database
/

CVE-2006-1895

Back to search

CVE-2006-1895

Published: Apr 20, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.

VendorProductVersions

n/a

n/a

affected
n/a

References

20060414 phpBB template file code execution
mailing-list
x_refsource_BUGTRAQ
17573
vdb-entry
x_refsource_BID
769
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now