CVE-2006-2152: High severity Phpbb Group Phpbb Advanced Guestbook vulnerability
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when registerglobals is enabled, allows remote attackers to include arbitrary files via the phpbbrootpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2152?
CVE-2006-2152 is a high severity vulnerability that allows remote attackers to execute arbitrary code.
How do I fix CVE-2006-2152?
To fix CVE-2006-2152, disable register_globals in your php.ini file and consider upgrading to a newer version of phpBB Advanced Guestbook.
What systems are affected by CVE-2006-2152?
CVE-2006-2152 affects phpBB Advanced Guestbook version 2.4.0 and earlier when register_globals is enabled.
What type of vulnerability is CVE-2006-2152?
CVE-2006-2152 is a remote file inclusion vulnerability that allows for the inclusion of arbitrary files.
Who can exploit CVE-2006-2152?
Any remote attacker can exploit CVE-2006-2152 if the vulnerable configuration is present.