CVE-2006-7147: Code Injection
Published Mar 7, 2007
·Updated
PHP remote file inclusion vulnerability in includes/functionsmoduser.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter.
Affected Software
2 affected components
phpBB Import Tools=0.1.3
phpBB Import Tools=0.1.4
Event History
Mar 7, 2007
CVE Published
08:19 PM
Mar 8, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7147?
CVE-2006-7147 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2006-7147?
To fix CVE-2006-7147, upgrade to phpBB Import Tools version 0.1.5 or later where the vulnerability is addressed.
3
What versions are affected by CVE-2006-7147?
CVE-2006-7147 affects phpBB Import Tools version 0.1.4 and earlier versions.
4
What type of vulnerability is CVE-2006-7147?
CVE-2006-7147 is a PHP remote file inclusion vulnerability that could lead to arbitrary code execution.
5
Who can exploit CVE-2006-7147?
CVE-2006-7147 can be exploited by remote attackers who can craft a malicious URL to execute arbitrary PHP code.