Phpbb · Phpbb · CVE-2006-4367
**Name of the Vulnerable Software and Affected Versions**
phpBB versions 2.0.21 and earlier, with All Topics Hack 1.5.0 and earlier
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `start` parameter in the alltopics.php file.
**Recommendations**
For phpBB versions 2.0.21 and earlier, with All Topics Hack 1.5.0 and earlier, consider restricting access to the alltopics.php file until a fix is available. Avoid using the `start` parameter in the affected API endpoint until the issue is resolved.