Vulnerabilities > CVE-2006-2134 - Remote File Include vulnerability in phpBB Knowledge Base Mod KB_constants.PHP

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
phpbb-group
exploit available

Summary

PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. Successful exploitation requires that "register_globals" is enabled.

Exploit-Db

descriptionKnowledge Base Mod <= 2.0.2 (phpBB) Remote Inclusion Vulnerability. CVE-2006-2134. Webapps exploit for php platform
fileexploits/php/webapps/1728.txt
idEDB-ID:1728
last seen2016-01-31
modified2006-04-29
platformphp
port
published2006-04-29
reporter[Oo]
sourcehttps://www.exploit-db.com/download/1728/
titleKnowledge Base Mod <= 2.0.2 phpBB Remote Inclusion Vulnerability
typewebapps