Vulnerabilities > CVE-2006-5526 - Unspecified vulnerability in Fully Modded PHPbb Fully Modded PHPbb
Summary
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, and (v) admin/admin_status.php in player/, different vectors than CVE-2006-3045. NOTE: CVE analysis as of 20061026 indicates that files in the admin/ and flash/ directories define foing_root_path before use.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Fully Modded phpBB <= 2021.4.40 Multiple File Include Vulnerabilities. CVE-2006-5526. Webapps exploit for php platform |
file | exploits/php/webapps/2621.txt |
id | EDB-ID:2621 |
last seen | 2016-01-31 |
modified | 2006-10-23 |
platform | php |
port | |
published | 2006-10-23 |
reporter | 020 |
source | https://www.exploit-db.com/download/2621/ |
title | Fully Modded phpBB <= 2021.4.40 - Multiple File Include Vulnerabilities |
type | webapps |
References
- http://secunia.com/advisories/22499
- http://secunia.com/advisories/22499
- http://www.osvdb.org/30035
- http://www.osvdb.org/30035
- http://www.vupen.com/english/advisories/2006/4165
- http://www.vupen.com/english/advisories/2006/4165
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29718
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29718
- https://www.exploit-db.com/exploits/2621
- https://www.exploit-db.com/exploits/2621