CVE-2006-5526
Fully Modded phpBB 2021.4.40 - Multiple File Inclusions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, and (v) admin/admin_status.php in player/, different vectors than CVE-2006-3045. NOTE: CVE analysis as of 20061026 indicates that files in the admin/ and flash/ directories define foing_root_path before use.
Vulnerabilidades de inclusión PHP de múltiples ficheros remotos en Teake Nutma Foing, como modificados en Fully Modded phpBB (phpbbfm) 2021.4.40 y anteriores, permite a atacantes remotos ejecutar código de su elección mediante un URL en el parámetro foing_root_path en a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, y (v) admin/admin_status.php in player/, vectores diferentes al CVE-2006-3045.
NOTA: El análisis de CVE del 20061026 indica que los ficheros de los directorios admin/ y flash/ definen foing_root_path antes de ser usado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-10-26 CVE Reserved
- 2006-10-26 CVE Published
- 2023-08-30 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.osvdb.org/30035 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/4165 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29718 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/2621 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/22499 | 2017-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fully Modded Phpbb Search vendor "Fully Modded Phpbb" | Fully Modded Phpbb Search vendor "Fully Modded Phpbb" for product "Fully Modded Phpbb" | <= 2021.4.40 Search vendor "Fully Modded Phpbb" for product "Fully Modded Phpbb" and version " <= 2021.4.40" | - |
Affected
|