CVE-2005-3420: High severity Phpbb Group Phpbb vulnerability
usercpregister.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signaturebbcodeuid parameter, as demonstrated by injecting an "e" modifier into a pregreplace statement.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3420?
CVE-2005-3420 is considered a critical vulnerability due to its ability to allow remote code execution via user input manipulation.
How do I fix CVE-2005-3420?
To remediate CVE-2005-3420, upgrade to a patched version of phpBB beyond 2.0.17, which addresses this vulnerability.
Which versions of phpBB are affected by CVE-2005-3420?
CVE-2005-3420 affects phpBB versions from 2.0.0 to 2.0.17, including all intermediate versions.
Can CVE-2005-3420 be exploited remotely?
Yes, CVE-2005-3420 can be exploited remotely by attackers who manipulate inputs to execute arbitrary PHP code.
What types of attacks are possible with CVE-2005-3420?
CVE-2005-3420 can lead to remote code execution attacks, allowing intruders to run unauthorized scripts on the server.