PT-2006-3613 · Phpbb+1 · Phpbb+1

Published

2006-05-31

·

Updated

2018-10-18

·

CVE-2006-2693

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nivisec Hacks List versions 1.20 and earlier
Description A directory traversal issue exists in the admin/admin hacks list.php file of Nivisec Hacks List for phpBB. When register globals is enabled, remote attackers can exploit this issue by using a ".." in the phpEx parameter to read arbitrary files.
Recommendations For Nivisec Hacks List versions 1.20 and earlier, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the admin/admin hacks list.php file until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2693

Affected Products

Nivisec Hacks List
Phpbb