Vulnerabilities > CVE-2006-2151 - Remote Security vulnerability in Phpbb Toplist

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpbb-group
exploit available

Summary

PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.

Vulnerable Configurations

Part Description Count
Application
Phpbb_Group
1

Exploit-Db

  • descriptionTopList <= 1.3.8 (phpBB Hack) Remote File Inclusion Vulnerability. CVE-2006-2151. Webapps exploit for php platform
    fileexploits/php/webapps/1722.txt
    idEDB-ID:1722
    last seen2016-01-31
    modified2006-04-27
    platformphp
    port
    published2006-04-27
    reporter[Oo]
    sourcehttps://www.exploit-db.com/download/1722/
    titleTopList <= 1.3.8 phpBB Hack Remote File Inclusion Vulnerability
    typewebapps
  • descriptionTopList <= 1.3.8 (phpBB Hack) Remote Inclusion Exploit. CVE-2006-2151. Webapps exploit for php platform
    fileexploits/php/webapps/1724.pl
    idEDB-ID:1724
    last seen2016-01-31
    modified2006-04-28
    platformphp
    port
    published2006-04-28
    reporterFOX_MULDER
    sourcehttps://www.exploit-db.com/download/1724/
    titleTopList <= 1.3.8 phpBB Hack Remote Inclusion Exploit
    typewebapps