Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpBB Page Header远程任意命令执行漏洞
Vulnerability Description
phpBB 1.4.0及其早期版本的prefs.php存在漏洞。远程认证用户借助无效的语言值执行任意PHP代码。该漏洞阻止变量(1)prefs.php中的$l_statsblock或者(2)auth.ph中的$l_privnotify适当的初始化。该漏洞可被用户修改然后用于eval描述。
CVSS Information
N/A
Vulnerability Type
N/A