V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2001-1471
DEB
HighConfirmedExploit available

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which p…

CVSS
8.8
High
EPSS
0.01
p79
Published
2001-01-01
Updated
2001-01-01
Description

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

Tags · CWE
CWE-665
CAPEC-26
CAPEC-29
Affected products
Phpbb ≤ 1.4.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2001-01-01
Published
2001-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.012 · p79
Known exploited (KEV)
No
Known exploits — Сканер-ВС
21065
exploitdb · https://www.exploit-db.com/exploits/21065
Enterprise
Affected software
ProductVendorStatus
phpbb2Tracked
phpbb*Tracked
Source databases
DEB
CVE