AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-1896

MEDIUM · CVSS 6 EPSS 1.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-04-20 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.0. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2006-1896
Severity
MEDIUM
CVSS
6
EPSS
1.28%

Original NVD Description

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.