Vulnerabilities > CVE-2006-2507 - Remote File Include vulnerability in Foing

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
teake-nutma
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) index.php, (2) song.php, (3) faq.php, (4) list.php, (5) gen_m3u.php, and (6) playlist.php.

Exploit-Db

descriptionFoing <= 0.7.0 (phpBB) Remote File Inclusion Vulnerability. CVE-2006-2507. Webapps exploit for php platform
idEDB-ID:1778
last seen2016-01-31
modified2006-05-12
published2006-05-12
reporterKurdish Security
sourcehttps://www.exploit-db.com/download/1778/
titleFoing <= 0.7.0 phpBB Remote File Inclusion Vulnerability