Vulnerabilities > CVE-2006-4631 - Remote Security vulnerability in SoftBB

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
softbb
exploit available

Summary

Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.

Vulnerable Configurations

Part Description Count
Application
Softbb
1

Exploit-Db

  • descriptionPHP-Proxima 6.0 BB_Smilies.PHP Local File Include Vulnerability. CVE-2006-4631. Webapps exploit for php platform
    idEDB-ID:28488
    last seen2016-02-03
    modified2006-09-04
    published2006-09-04
    reporterKacper
    sourcehttps://www.exploit-db.com/download/28488/
    titlePHP-Proxima 6.0 BB_Smilies.PHP Local File Include Vulnerability
  • idEDB-ID:2300