Description: A weakness and a vulnerability have been discovered in phpBB, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to use it for making HTTP requests to other sites.
1) A design error in the "Upload Avatar from a URL" functionality can be exploited to cause the server to make HTTP GET requests to arbitrary remote sites.
Successful exploitation requires that the "Enable avatar uploading" setting is enabled (disabled by default).
2) Input passed to the "Font Colour 3" field isn't properly sanitised before being used in a "preg_replace()" call with the "e" modifier. This can be exploited to inject and execute arbitrary PHP code.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.