Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose .* regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpbb | Phpbb_group | 2.0.9 (including) | 2.0.9 (including) |
Phpbb2 | Ubuntu | dapper | * |
Phpbb2 | Ubuntu | edgy | * |
Phpbb2 | Ubuntu | feisty | * |
Phpbb2 | Ubuntu | gutsy | * |