Vulnerabilities > CVE-2006-2152 - Unspecified vulnerability in PHPbb Group PHPbb Advanced Guestbook
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Advanced GuestBook <= 2.4.0 (phpBB) File Inclusion Vulnerability. CVE-2006-2152. Webapps exploit for php platform file exploits/php/webapps/1723.txt id EDB-ID:1723 last seen 2016-01-31 modified 2006-04-28 platform php port published 2006-04-28 reporter [Oo] source https://www.exploit-db.com/download/1723/ title Advanced GuestBook <= 2.4.0 - phpBB File Inclusion Vulnerability type webapps id EDB-ID:1725
Nessus
NASL family | CGI abuses |
NASL id | ADVANCED_GUESTBOOK_PHPBB_ROOT_PATH_FILE_INCLUDE.NASL |
description | The remote host is running Advanced Guestbook, a free guestbook written in PHP. The version of Advanced Guestbook installed on the remote host fails to sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21302 |
published | 2006-05-03 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/21302 |
title | phpBB Advanced GuestBook addentry.php phpbb_root_path Parameter Remote File Inclusion |
References
- http://secunia.com/advisories/19905
- http://secunia.com/advisories/19905
- http://www.securityfocus.com/bid/17745
- http://www.securityfocus.com/bid/17745
- http://www.vupen.com/english/advisories/2006/1600
- http://www.vupen.com/english/advisories/2006/1600
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26217
- https://www.exploit-db.com/exploits/1723
- https://www.exploit-db.com/exploits/1723
- https://www.exploit-db.com/exploits/1725
- https://www.exploit-db.com/exploits/1725