vendor:
phpBB mutant
by:
bd0rk
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: phpBB mutant
Affected Version From: 2000.9.2
Affected Version To: 2000.9.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
phpBB mutant 0.9.2 (phpbb_root_path) Remote File Inclusion Exploit
This exploit targets a vulnerability in phpBB mutant 0.9.2 where the 'phpbb_root_path' variable is not properly declared before inclusion, allowing remote files to be included. By exploiting this vulnerability, an attacker can execute arbitrary remote code.
Mitigation:
The vendor should release a patch that properly declares the 'phpbb_root_path' variable before inclusion. Additionally, it is recommended to keep the software up to date and apply any available security patches.