Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user's php file for this account. NOTE: similar code injection might be possible in a user profile.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-12-17T18:00:00

Updated: 2018-10-15T20:57:01

Reserved: 2007-12-17T00:00:00


Link: CVE-2007-6396

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-12-17T18:46:00.000

Modified: 2018-10-15T21:52:54.157


Link: CVE-2007-6396

JSON object: View

cve-icon Redhat Information

No data.

CWE