PT-2006-5784 · Joomla · Joomlaboard Forum

Cold Zero

·

Published

2006-09-27

·

Updated

2024-02-14

·

CVE-2006-5043

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Joomlaboard Forum Component (com joomlaboard) versions prior to 1.1.2
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to specific PHP files, including file upload.php and image upload.php.
Recommendations For versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload.php and image upload.php files until the update is applied. Avoid using the sbp parameter in these files until the issue is resolved.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2006-5043

Affected Products

Joomlaboard Forum