CVE-2007-5100: Code Injection
Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a before 20070922, when registerglobals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the phpbbrootpath parameter to (1) language/langgerman/langadminalbum.php, (2) language/langenglish/langmainalbum.php, and (3) language/langenglish/langadminalbum.php, different vectors than CVE-2007-5009.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5100?
CVE-2007-5100 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2007-5100?
To remediate CVE-2007-5100, disable register_globals and upgrade to phpBB Plus version 1.53b or later.
What types of attacks can exploit CVE-2007-5100?
CVE-2007-5100 can be exploited by remote attackers using malicious URLs in the phpbb_root_path parameter.
What software is affected by CVE-2007-5100?
CVE-2007-5100 affects phpBB Plus versions 1.53 and 1.53a prior to 20070922.
Is there a patch available for CVE-2007-5100?
Yes, upgrading to the latest version of phpBB Plus provides a patch for CVE-2007-5100.