Vulnerabilities > CVE-2006-2361 - Remote File Include vulnerability in PAFileDB Pafiledb_Constants.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mxbb
php-arena
exploit available

Summary

PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

Vulnerable Configurations

Part Description Count
Application
Mxbb
2
Application
Php_Arena
2

Exploit-Db

descriptionpafileDB <= 2.0.1 (mxBB/phpBB) Remote File Inclusion Vulnerability. CVE-2006-2361. Webapps exploit for php platform
fileexploits/php/webapps/1774.txt
idEDB-ID:1774
last seen2016-01-31
modified2006-05-09
platformphp
port
published2006-05-09
reporterDarkfire
sourcehttps://www.exploit-db.com/download/1774/
titlepafileDB <= 2.0.1 mxBB/phpBB Remote File Inclusion Vulnerability
typewebapps