Description
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
Remediation
References
Related Vulnerabilities
silverstripeCMS Other Vulnerability (CVE-2007-2321)
MediaWiki Improper Access Control Vulnerability (CVE-2015-8001)
WordPress Plugin Localize My Post Local File Inclusion (1.0)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'nggallery-manage-gallery' HTML Injection (0.96)
Next.js Acceptance of Extraneous Untrusted Data With Trusted Data Vulnerability (CVE-2026-44572)