vendor:
Flashbb
by:
kw3rln
5.5
CVSS
MEDIUM
Remote File Inclusion
CWE
Product Name: Flashbb
Affected Version From: 1.1.2000
Affected Version To: 1.1.2007
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Flashbb <= 1.1.7 - Remote File Inclusion Exploit
This exploit takes advantage of a vulnerability in Flashbb version 1.1.7, allowing remote file inclusion. By manipulating the 'phpbb_root_path' parameter in the 'sendmsg.php' file, an attacker can execute arbitrary code on the target system. The exploit URL format is 'http://site.com/[path]/phpbb/sendmsg.php?phpbb_root_path=[Evil_Script>]'.
Mitigation:
To mitigate this vulnerability, it is recommended to update Flashbb to a newer version that does not have this issue.