Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1895

Опубликовано: 20 апр. 2006
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpbb_group:phpbb:2.0.9:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00365
Низкий

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 19 лет назад

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.

debian
больше 19 лет назад

Direct static code injection vulnerability in includes/template.php in ...

github
больше 3 лет назад

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.

EPSS

Процентиль: 56%
0.00365
Низкий

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other