CVE-2001-1471

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpbb_group:phpbb:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:phpbb_group:phpbb:1.2.0:*:*:*:*:*:*:*

Information

Published : 2001-07-31 04:00

Updated : 2017-07-11 01:29


NVD link : CVE-2001-1471

Mitre link : CVE-2001-1471


JSON object : View

Products Affected

phpbb_group

  • phpbb