PT-2006-4556 · Minibb · Minibb Forum

Ahmad Maulana

+1

·

Publicado

2006-07-18

·

Atualizado

2018-10-18

·

CVE-2006-3690

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MiniBB Forum versions 1.5a and earlier
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the absolute path parameter to API endpoints such as "components/com minibb.php" or "components/minibb/index.php".
Recommendations For MiniBB Forum versions 1.5a and earlier, consider restricting access to the components/com minibb.php and components/minibb/index.php API endpoints until a patch is available. Avoid using the absolute path parameter in these endpoints to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3690

Produtos afetados

Minibb Forum