CVE-2006-1896: Code Injection
Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1896?
CVE-2006-1896 has a severity level that can lead to remote code execution for authenticated users.
How do I fix CVE-2006-1896?
To fix CVE-2006-1896, update your phpBB installation to the latest version that addresses this vulnerability.
Who is affected by CVE-2006-1896?
CVE-2006-1896 affects phpBB installations where authenticated users have access to the Administration Panel.
What type of vulnerability is CVE-2006-1896?
CVE-2006-1896 is an arbitrary code execution vulnerability due to improper handling of user input.
Can I prevent CVE-2006-1896 exploitation?
To prevent exploitation of CVE-2006-1896, limit access to the Administration Panel and ensure you're running a patched version of phpBB.