CVE-2007-5173: Code Injection
Published Oct 3, 2007
·Updated
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openidrootpath parameter.
Affected Software
2 affected components
phpBB phpbb
Openid OpenID=0.2.0
Event History
Oct 3, 2007
CVE Published
02:17 PM
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5173?
CVE-2007-5173 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2007-5173?
To fix CVE-2007-5173, you should upgrade to a patched version of phpBB and the OpenID extension.
3
What systems are affected by CVE-2007-5173?
CVE-2007-5173 affects phpBB with the Openid extension version 0.2.0.
4
What type of vulnerability is CVE-2007-5173?
CVE-2007-5173 is a remote file inclusion vulnerability.
5
Can CVE-2007-5173 be exploited remotely?
Yes, CVE-2007-5173 can be exploited remotely by attackers through maliciously crafted URLs.