CVE-2006-2134: Medium severity Phpbb Group Phpbb vulnerability
Published May 2, 2006
·Updated
PHP remote file inclusion vulnerability in /includes/kbconstants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the modulerootpath parameter.
Affected Software
16 affected components
Phpbb Group Phpbb<=2.0.2
Phpbb Group Phpbb=1.0.0
Phpbb Group Phpbb=1.0.1
Phpbb Group Phpbb=1.2.0
Phpbb Group Phpbb=1.2.1
Phpbb Group Phpbb=1.4.0
Phpbb Group Phpbb=1.4.1
Phpbb Group Phpbb=1.4.2
Phpbb Group Phpbb=1.4.4
Phpbb Group Phpbb=2.0.0
Phpbb Group Phpbb=2.0.1
Phpbb Group Phpbb=2.0_beta1
Phpbb Group Phpbb=2.0_rc1
Phpbb Group Phpbb=2.0_rc2
Phpbb Group Phpbb=2.0_rc3
Phpbb Group Phpbb=2.0_rc4
Event History
May 2, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2134?
The severity of CVE-2006-2134 is considered to be critical due to its potential for remote code execution.
2
How do I fix CVE-2006-2134?
To fix CVE-2006-2134, you should upgrade to a patched version of PHPbb that is higher than 2.0.2.
3
Which versions are affected by CVE-2006-2134?
CVE-2006-2134 affects PHPbb versions 2.0.2 and earlier, including specific versions like 1.2.1 and 1.4.4.
4
What type of vulnerability is CVE-2006-2134?
CVE-2006-2134 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
5
Can CVE-2006-2134 be exploited without authentication?
Yes, CVE-2006-2134 can be exploited without authentication, making it particularly dangerous.