CVE-2006-1896

Publication date 20 April 2006

Last updated 17 July 2025


Ubuntu priority

Description

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.

Status

Package Ubuntu Release Status
phpbb2 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid
Fixed 2.0.21-3
8.04 LTS hardy
Fixed 2.0.21-3
7.10 gutsy
Fixed 2.0.21-3
7.04 feisty
Fixed 2.0.21-3
6.10 edgy
Fixed 2.0.21-3
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities