Loading
Generated remediation guidance and an executive summary. No account required.
usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.
Use Phpbb Group vendor hub and Phpbb product page to widen CVE-2005-3420 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-1695, CVE-2006-6841 and CVE-2006-6840 for nearby disclosures in the same product family.