High severity8.8NVD Advisory· Published Jul 31, 2001· Updated Apr 16, 2026
CVE-2001-1471
CVE-2001-1471
Description
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securityfocus.com/bid/3167nvdBroken LinkExploitPatchThird Party AdvisoryVDB Entry
- www.kb.cert.org/vuls/id/920931nvdThird Party AdvisoryUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/6944nvdThird Party AdvisoryVDB Entry
- archives.neohapsis.com/archives/bugtraq/2001-08/0123.htmlnvdBroken Link
- www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-08/0087.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.