Vulnerabilities > CVE-2006-4631 - Remote Security vulnerability in SoftBB
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description PHP-Proxima 6.0 BB_Smilies.PHP Local File Include Vulnerability. CVE-2006-4631. Webapps exploit for php platform id EDB-ID:28488 last seen 2016-02-03 modified 2006-09-04 published 2006-09-04 reporter Kacper source https://www.exploit-db.com/download/28488/ title PHP-Proxima 6.0 BB_Smilies.PHP Local File Include Vulnerability id EDB-ID:2300
References
- http://acid-root.new.fr/advisories/10060904.txt
- http://secunia.com/advisories/21761
- http://securityreason.com/securityalert/1521
- http://securitytracker.com/id?1016785
- http://www.osvdb.org/28579
- http://www.securityfocus.com/archive/1/445087/100/0/threaded
- http://www.vupen.com/english/advisories/2006/3478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28749
- https://www.exploit-db.com/exploits/2300