CVE-2006-1896

Publication date 20 April 2006

Last updated 24 July 2024


Ubuntu priority

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
phpbb2 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid
Fixed 2.0.21-3
8.04 LTS hardy
Fixed 2.0.21-3
7.10 gutsy
Fixed 2.0.21-3
7.04 feisty
Fixed 2.0.21-3
6.10 edgy
Fixed 2.0.21-3
6.06 LTS dapper Ignored end of life