5.1
CVSSv2

CVE-2006-2914

Published: 23/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote malicious users to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php, and (6) pm/newpm.php in the default/ directory.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.06

Exploits

Secunia Research has discovered some vulnerabilities in DeluxeBB, which can be exploited by malicious people to conduct SQL injection attacks and compromise a vulnerable system 1) Input passed to the "templatefolder" parameter in various scripts isn't properly verified, before it is used to include files This can be exploited to include arbitrar ...
Secunia Research has discovered some vulnerabilities in DeluxeBB version 106, which can be exploited by malicious people to conduct SQL injection attacks and compromise a vulnerable system ...