Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3) member.php, (4) mail.php, (5) lostpassword.php, (6) gesfil.php, (7) forum82lib.php3, and other unspecified scripts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forum82 | Forum82 | <= 2.5.2b |
References
- http://secunia.com/advisories/22214Vendor Advisory
- http://www.securityfocus.com/bid/20291Exploit
- http://www.vupen.com/english/advisories/2006/3865
- https://www.exploit-db.com/exploits/2459
- http://secunia.com/advisories/22214Vendor Advisory
- http://www.securityfocus.com/bid/20291Exploit
- http://www.vupen.com/english/advisories/2006/3865
- https://www.exploit-db.com/exploits/2459
FAQ
What is CVE-2006-5148?
CVE-2006-5148 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /fo...
How severe is CVE-2006-5148?
CVE-2006-5148 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5148?
Check the references section above for vendor advisories and patch information. Affected products include: Forum82 Forum82.