CVE-2006-7168: High severity phpBB phpbb vulnerability
Published Mar 20, 2007
·Updated
PHP remote file inclusion vulnerability in includes/notmem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter.
Affected Software
1 affected component
phpBB phpbb
Event History
Mar 20, 2007
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7168?
CVE-2006-7168 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-7168?
To fix CVE-2006-7168, you should update to a patched version of the phpBB software that addresses this vulnerability.
3
What systems are affected by CVE-2006-7168?
CVE-2006-7168 affects phpBB installations that utilize the 'Add Name' module with the included not_mem.php script.
4
What type of attack does CVE-2006-7168 enable?
CVE-2006-7168 enables remote attackers to execute arbitrary PHP code on the server.
5
Is there a workaround for CVE-2006-7168?
A potential workaround for CVE-2006-7168 is to disable the Add Name module until the software is updated.