CVE-2006-2245: Code Injection
PHP remote file inclusion vulnerability in auction\auctioncommon.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2245?
CVE-2006-2245 has a high severity due to its potential for remote execution of arbitrary PHP code.
How do I fix CVE-2006-2245?
To fix CVE-2006-2245, it is recommended to upgrade to a secure version of the Auction mod for phpBB that does not contain this vulnerability.
What software is affected by CVE-2006-2245?
CVE-2006-2245 affects Auction mod versions 1.0m, 1.2m, and 1.3m for phpBB.
What are the implications of CVE-2006-2245 vulnerability?
The CVE-2006-2245 vulnerability allows remote attackers to execute arbitrary PHP code, potentially leading to a complete compromise of the affected system.
Can CVE-2006-2245 be exploited easily?
Yes, CVE-2006-2245 can be exploited with relatively simple techniques by manipulating the phpbb_root_path parameter.