Vulnerabilities > CVE-2006-5222 - Remote File Include vulnerability in Dimension of PHPbb Dimension of PHPbb 0.2.6

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
dimension-of-phpbb
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2) includes/logger_engine.php.

Vulnerable Configurations

Part Description Count
Application
Dimension_Of_Phpbb
1

Exploit-Db

descriptionDimension of phpBB <= 0.2.6 (phpbb_root_path) Remote File Includes. CVE-2006-5222. Webapps exploit for php platform
fileexploits/php/webapps/2481.txt
idEDB-ID:2481
last seen2016-01-31
modified2006-10-05
platformphp
port
published2006-10-05
reporterSpiderZ
sourcehttps://www.exploit-db.com/download/2481/
titleDimension of phpBB <= 0.2.6 phpbb_root_path Remote File Includes
typewebapps