Package: phpbb2
Severity: grave
Tags: security
Justification: user security hole


CVE-2006-1895:

Direct static code injection vulnerability in includes/template.php in
phpBB allows remote authenticated users with write access to execute
arbitrary PHP code by modifying a template in a way that (1) bypasses
a loose ".*" regular expression to match BEGIN and END statements in
overall_header.tpl, or (2) is used in an eval statement by
includes/bbcode.php for bbcode.tpl.

See:
http://www.securityfocus.com/archive/1/archive/1/431017/100/0/threaded


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to