PT-2006-3613 · Phpbb+1 · Phpbb+1
Published
2006-05-31
·
Updated
2018-10-18
·
CVE-2006-2693
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nivisec Hacks List versions 1.20 and earlier
Description
A directory traversal issue exists in the admin/admin hacks list.php file of Nivisec Hacks List for phpBB. When register globals is enabled, remote attackers can exploit this issue by using a ".." in the
phpEx parameter to read arbitrary files.Recommendations
For Nivisec Hacks List versions 1.20 and earlier, consider disabling the
register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the admin/admin hacks list.php file until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nivisec Hacks List
Phpbb