peter bassill · operator
$ cve CVE-2006-5526 JSON

CVE-2006-5526 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, and (v) admin/admin_status.php in player/, different vectors than CVE-2006-3045. NOTE: CVE analysis as of 20061026 indicates that files in the admin/ and flash/ directories define foing_root_path before use.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.95% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2006-10-26
Last modified2026-06-16

Affected (1)

VendorProduct
fully modded phpbbfully modded phpbb

Public exploits

SourceTitleDate
exploit-dbFully Modded phpBB 2021.4.40 - Multiple File Inclusions2006-10-23

References

→ the Explorer  ·  watch your stack  ·  NVD