6.8
CVSSv2

CVE-2006-7208

Published: 26/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and previous versions for Mambo allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

adam van dongen phpbb component 1.2.4rc3

adam van dongen com forum 1.2.4rc3

Exploits

Bug Found by h4ntu [h4ntucom] #batamhacker crew Another Mambo component remote inclusion vulneribility download : mamboxchangecom/frs/downloadphp/6873/phpbb_component124RC3zip bug found in file : downloadphp define('IN_PHPBB', true); //$phpbb_root_path = '/'; include($phpbb_root_path 'extensioninc '); include($phpbb_root ...