Sunday, December 25. 2005
At Halloween 2005 I had
disclosed a number of bugs in phpBB, including a remote code execution exploit through the
signature_bbcode_uid variable. You will not find this vulnerability in the
phpBB security tracker because it is phpBB project's practise to blame their bugs on PHP and/or otherwise downplay them or hide them. Unfortunately there is now a
public exploit for this vulnerability, which was released yesterday while most of us were celebrating christmas.