7.5
CVSSv2

CVE-2006-2865

Published: 06/06/2006 Updated: 11/04/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote malicious users to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a site-specific vulnerability, or an issue in a mod

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.20

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.16

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0_rc2

phpbb group phpbb 2.0

phpbb group phpbb 2.0_rc1

phpbb group phpbb 2.0.19

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.9

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0.15

phpbb group phpbb 2.0_rc4

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.17

phpbb group phpbb 2.0_rc3

phpbb group phpbb 2.0.18

phpbb group phpbb 2.0_beta1

Exploits

source: wwwsecurityfocuscom/bid/18255/info The phpBB application is prone to a remote file-include vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of ...