CVE-2006-5435: High severity Phpbb Group Phpbb vulnerability
DISPUTED PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter. NOTE: CVE and the vendor dispute this vulnerability because $phpbbrootpath is defined before use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5435?
CVE-2006-5435 is considered a remote file inclusion vulnerability that could allow attackers to execute arbitrary PHP code.
How do I fix CVE-2006-5435?
To mitigate CVE-2006-5435, it is recommended to upgrade phpBB to version 2.0.11 or later, which addresses this vulnerability.
What versions of phpBB are affected by CVE-2006-5435?
CVE-2006-5435 affects phpBB version 2.0.10 and earlier.
Can CVE-2006-5435 be exploited remotely?
Yes, CVE-2006-5435 can be exploited remotely by attackers to execute arbitrary PHP code.
Is the vulnerability in CVE-2006-5435 disputed?
Yes, there is a dispute regarding the vulnerability in CVE-2006-5435, as the variable $phpbb_root_path is defined before use.