CVE-2005-3420
CVE-2005-3420
usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://marc.info/?l=bugtraq&m=113081113317600&w=2http://secunia.com/advisories/17366http://secunia.com/advisories/18098http://securityreason.com/securityalert/130http://securitytracker.com/id?1015121http://www.debian.org/security/2005/dsa-925http://www.hardened-php.net/advisory_172005.75.htmlhttp://www.osvdb.org/20391http://www.securityfocus.com/bid/15243http://www.vupen.com/english/advisories/2005/2250