Vulnerabilities > CVE-2006-2739 - Input Validation vulnerability in tinyBB

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
epic-designs
exploit available

Summary

PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter. Successful exploitation requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Epic_Designs
1

Exploit-Db

descriptiontinyBB <= 0.3 Remote (Include / SQL Injection) Vulnerabilities. CVE-2006-2739,CVE-2006-2740. Webapps exploit for php platform
idEDB-ID:1839
last seen2016-01-31
modified2006-05-28
published2006-05-28
reporternukedx
sourcehttps://www.exploit-db.com/download/1839/
titletinyBB <= 0.3 - Remote Include / SQL Injection Vulnerabilities