PT-2007-3817 · Mxbb · Mxbb Faq & Rules Module

Bd0Rk

·

Published

2007-05-04

·

Updated

2017-10-11

·

CVE-2007-2493

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mxBB FAQ & RULES module versions 2.0.0 and earlier
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the module root path parameter in the faq.php file of the FAQ & RULES module for mxBB.
Recommendations For mxBB FAQ & RULES module versions 2.0.0 and earlier, consider restricting access to the faq.php file until a patch is available, and avoid using the module root path parameter in the affected module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2493

Affected Products

Mxbb Faq & Rules Module