Forum82 · Forum82 · CVE-2006-5148
**Name of the Vulnerable Software and Affected Versions**
Forum82 versions 2.5.2b and earlier
**Description**
The issue allows remote attackers to execute arbitrary PHP code via a URL in the `repertorylevel` parameter, including scripts such as "search.php", "message.php", "member.php", "mail.php", "lostpassword.php", "gesfil.php", "forum82lib.php3", and other unspecified scripts.
**Recommendations**
For Forum82 versions 2.5.2b and earlier, consider restricting access to the `repertorylevel` parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the `repertorylevel` parameter in affected scripts.