CVE-2006-7148: Critical severity phpBB maluinfo vulnerability
Published Mar 7, 2007
·Updated
PHP remote file inclusion vulnerability in includes/bbusagestats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbbrootpath parameter. NOTE: this might be the same issues as CVE-2006-4893.
Affected Software
1 affected component
phpBB maluinfo=206.2.38
Event History
Mar 7, 2007
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7148?
CVE-2006-7148 is considered high severity due to its potential to allow remote command execution via PHP code.
2
How do I fix CVE-2006-7148?
To fix CVE-2006-7148, update the PHPBB Maluinfo to a version that is not vulnerable such as later versions than 206.2.38.
3
What software is affected by CVE-2006-7148?
CVE-2006-7148 affects the PHPBB Maluinfo version 206.2.38.
4
What kind of attack can be executed due to CVE-2006-7148?
CVE-2006-7148 allows remote attackers to execute arbitrary PHP code on the server.
5
Is CVE-2006-7148 still a concern today?
Yes, CVE-2006-7148 remains a concern for systems using the vulnerable software version without proper updates.