vendor:
phpBB
by:
SecureD
9,3
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: phpBB
Affected Version From: 2.0.15
Affected Version To: 2.0.15
Patch Exists: YES
Related CWE: CVE-2006-6184
CPE: a:phpbb:phpbb:2.0.15
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2006
phpBB 2.0.15 Viewtopic.PHP Remote Code Execution Vulnerability
This exploit gives the user all the details about the database connection such as database host, username, password and database name.
Mitigation:
Upgrade to phpBB 2.0.16 or later