vendor:
PHPbbBook
by:
Osirys
9.3
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: PHPbbBook
Affected Version From: 1.3
Affected Version To: 1.3h
Patch Exists: NO
Related CWE: N/A
CPE: a:phpbbbook:phpbbbook:1.3h
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2009
PHPbbBook RCE Exploit via Log Inj
This exploit allows an attacker to inject malicious code into the Apache log files and execute arbitrary commands on the vulnerable system.
Mitigation:
Ensure that the web server is configured to prevent remote code execution.