CVE Vulnerabilities

CVE-2007-1695

Published: Mar 27, 2007 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly

Affected Software

Name Vendor Start Version End Version
Phpbb Phpbb_group 2.0.19 (including) 2.0.19 (including)
Phpbb2 Ubuntu dapper *
Phpbb2 Ubuntu edgy *
Phpbb2 Ubuntu feisty *
Phpbb2 Ubuntu gutsy *
Phpbb2 Ubuntu hardy *
Phpbb2 Ubuntu intrepid *

References