CVE-2006-7174: Critical severity phpBB Dimension vulnerability
Published Mar 21, 2007
·Updated
PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter. NOTE: this may be the same issue as CVE-2006-5235.
Affected Software
1 affected component
phpBB Dimension
Event History
Mar 21, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7174?
CVE-2006-7174 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2006-7174?
To fix CVE-2006-7174, it is recommended to update to the latest version of phpBB that addresses this vulnerability.
3
What software is affected by CVE-2006-7174?
The phpBB Dimension module is affected by CVE-2006-7174.
4
How does CVE-2006-7174 work?
CVE-2006-7174 allows attackers to execute arbitrary PHP code by exploiting a remote file inclusion vulnerability through the phpbb_root_path parameter.
5
Is CVE-2006-7174 related to any other vulnerabilities?
CVE-2006-7174 may be related to CVE-2006-5235, indicating a similar exploitation mechanism.