vendor:
codebb
by:
Alkomandoz Hacker
5.5
CVSS
MEDIUM
Remote File Include
22
CWE
Product Name: codebb
Affected Version From: 1.1b3
Affected Version To: 1.1b3
Patch Exists: NO
Related CWE:
CPE: a:codebb:codebb:1.1b3
Platforms Tested:
2007
codebb 1.1b3 (phpbb_root_path) Remote File Include Vulnerability
The vulnerability allows an attacker to include a remote file by manipulating the 'phpbb_root_path' parameter in the 'pass_code.php' and 'lang_select' files of codebb 1.1b3.
Mitigation:
Update to a version that is not vulnerable or apply patches if available.