vendor:
phpBB
by:
Unknown
7.5
CVSS
HIGH
Remote code execution
CWE
Product Name: phpBB
Affected Version From: 2.0.6
Affected Version To: 2.0.10
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
phpBB <= 2.0.10 remote commands exec exploit
This is a Perl script that exploits a vulnerability in phpBB version 2.0.10 and below to execute remote commands. The exploit takes advantage of a security issue related to search highlighting. The script has been successfully tested on versions 2.0.6, 2.0.8, 2.0.9, and 2.0.10. The exploit allows an attacker to execute arbitrary commands on the target system.
Mitigation:
Upgrade to a patched version of phpBB.