10
CVSSv2

CVE-2007-2493

Published: 04/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and previous versions module for mxBB allows remote malicious users to execute arbitrary PHP code via a URL in the module_root_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mxbb mxbb faq

mxbb mxbb rules

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? print ' mxBB Module MX Faq & Rules <= 200 (faqphp) Remote File Include Exploit [Vendor: wwwmx-systemcom/modules/mx_pafiledb/dloadphp?action=download&file_id=371 Bug found and Exploit by bd0rk from SOH-Crew Website1: wwwhackschooldlam Website2: wwwsoh-crewittt Contac ...