Package: phpbb2
Severity: grave
Tags: security
Justification: user security hole

CVE-2006-1896:
Unspecified vulnerability in phpBB allows remote authenticated users
with Administration Panel access to execute arbitrary PHP code via
crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature
values, possibly involving the highlight functionality.  NOTE: the
original report does not clarigy whether this issue is static code
injection, eval injection, or another type of vulnerability.

See
http://www.securityfocus.com/archive/1/archive/1/431015/100/0/threaded


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to