CVE Vulnerabilities

CVE-2007-1695

Published: Mar 27, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly

Affected Software

NameVendorStart VersionEnd Version
PhpbbPhpbb_group2.0.19 (including)2.0.19 (including)
Phpbb2Ubuntudapper*
Phpbb2Ubuntuedgy*
Phpbb2Ubuntufeisty*
Phpbb2Ubuntugutsy*
Phpbb2Ubuntuhardy*
Phpbb2Ubuntuintrepid*

References