CVE-2006-1896
Last modified
CVE-2006-1896 is a vulnerability of currently unknown severity. Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpbb Group | Phpbb | All versions |
References
- http://secunia.com/advisories/20093Vendor Advisory
- http://secunia.com/advisories/20197Patch, Vendor Advisory
- http://secunia.com/advisories/20093Vendor Advisory
- http://secunia.com/advisories/20197Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1896?
How severe is CVE-2006-1896?
How do I fix CVE-2006-1896?
Are you affected by CVE-2006-1896?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
