Vulnerabilities > CVE-2006-2914 - Remote File Include vulnerability in Deluxebb 1.06

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
deluxebb
exploit available

Summary

PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php, and (6) pm/newpm.php in the default/ directory.

Vulnerable Configurations

Part Description Count
Application
Deluxebb
1

Exploit-Db

descriptionDeluxeBB <= 1.06 (templatefolder) Remote File Include Vulnerabilities. CVE-2006-2914. Webapps exploit for php platform
idEDB-ID:1916
last seen2016-01-31
modified2006-06-15
published2006-06-15
reporterAndreas Sandblad
sourcehttps://www.exploit-db.com/download/1916/
titleDeluxeBB <= 1.06 templatefolder Remote File Include Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/47543/secunia-deluxebb.txt
idPACKETSTORM:47543
last seen2016-12-05
published2006-06-21
reporterAndreas Sandblad
sourcehttps://packetstormsecurity.com/files/47543/secunia-deluxebb.txt.html
titlesecunia-deluxebb.txt