CVE-2006-5390: Code Injection
PHP remote file inclusion vulnerability in includes/functionsmoduser.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5390?
CVE-2006-5390 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary PHP code.
How do I fix CVE-2006-5390?
To fix CVE-2006-5390, users should update to a patched version of the ACP User Registration module that addresses this vulnerability.
What are the risks associated with CVE-2006-5390?
The risks associated with CVE-2006-5390 include unauthorized access and control over the affected system, leading to potential data breaches.
Which versions are affected by CVE-2006-5390?
CVE-2006-5390 specifically affects version 1.00 of the ACP User Registration module for phpBB.
Who is impacted by CVE-2006-5390?
Users of phpBB who have installed the ACP User Registration module version 1.00 are impacted by CVE-2006-5390.