8.8
CVSSv3

CVE-2001-1471

Published: 31/07/2001 Updated: 15/02/2024
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

prefs.php in phpBB 1.4.0 and previous versions allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb phpbb

Exploits

source: wwwsecurityfocuscom/bid/3167/info An input validation error exists in phpBB, a freely available WWW forums package The problem is due to improper validation of some variables in phpBB It is possible for users registered with the phpBB system to submit values for certain variables used internally by some scripts in the package ...