vendor:
phpBB Module Forum picture and META tags
by:
bd0rk
7.5
CVSS
HIGH
File Include
CWE
Product Name: phpBB Module Forum picture and META tags
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
phpBB Module Forum picture and META tags 1.7 File Include Vulnerability
This vulnerability exists in the phpBB Module Forum picture and META tags 1.7. It allows an attacker to include arbitrary files by exploiting the 'MOD_forum_fields_parse.php' script, which does not properly declare the 'phpbb_root_path' variable. By manipulating the 'phpbb_root_path' parameter in the URL, an attacker can include any file on the server.
Mitigation:
The vendor should release a patch to properly declare the 'phpbb_root_path' variable in the script. Until a patch is available, users should remove or disable the vulnerable module.