First published: Fri Jan 04 2008(Updated: )
Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pnphpbb | =1.2.0_i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6624 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2007-6624, upgrade to a patched version of PNphpBB2 that addresses the directory traversal vulnerability.
The risks associated with CVE-2007-6624 include unauthorized file inclusion and possible execution of malicious code on the server.
If you are using PNphpBB2 version 1.2.0_i or earlier, your application is affected by CVE-2007-6624.
Any remote attacker with knowledge of the vulnerability can exploit CVE-2007-6624 to execute arbitrary local files on the server.