Vulnerabilities > CVE-2006-5209 - Remote Security vulnerability in phpBB

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpbb-group
exploit available

Summary

PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

Exploit-Db

descriptionphpBB Admin Topic Action Logging Mod <= 0.94b File Include Vuln. CVE-2006-5209. Webapps exploit for php platform
fileexploits/php/webapps/2475.txt
idEDB-ID:2475
last seen2016-01-31
modified2006-10-04
platformphp
port
published2006-10-04
reporterSpiderZ
sourcehttps://www.exploit-db.com/download/2475/
titlephpBB Admin Topic Action Logging Mod <= 0.94b File Include Vuln
typewebapps