7.5
CVSSv2

CVE-2005-2633

Published: 23/08/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 775
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board 2.0 and previous versions allow remote malicious users to execute arbitrary PHP code via the absolutepath parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phptb topic boards

Exploits

source: wwwsecurityfocuscom/bid/14592/info PHPTB is prone to multiple remote file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges ...
source: wwwsecurityfocuscom/bid/14592/info PHPTB is prone to multiple remote file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges of ...
source: wwwsecurityfocuscom/bid/14592/info PHPTB is prone to multiple remote file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileg ...
source: wwwsecurityfocuscom/bid/14592/info PHPTB is prone to multiple remote file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privil ...
source: wwwsecurityfocuscom/bid/14592/info PHPTB is prone to multiple remote file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges o ...