Vulnerabilities > CVE-2006-5735 - File-Upload vulnerability in Punbb
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the language parameter, related to register.php storing a language value in the users table.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | PUNBB_REGISTER_LFI.NASL |
description | The version of PunBB installed on the remote host fails to sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22932 |
published | 2006-11-03 |
reporter | This script is Copyright (C) 2006-2018 Justin Seitz |
source | https://www.tenable.com/plugins/nessus/22932 |
title | PunBB include/common.php language Parameter Local File Inclusion |
References
- http://secunia.com/advisories/22622
- http://securityreason.com/securityalert/1824
- http://securitytracker.com/id?1017131
- http://www.osvdb.org/30132
- http://www.punbb.org/changelogs/1.2.13_to_1.2.14.txt
- http://www.securityfocus.com/archive/1/450055/100/0/threaded
- http://www.vupen.com/english/advisories/2006/4256
- http://www.wargan.org/index.php/2006/10/29/4-punbb-1213-multiple-vulnerabilities