Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid 2.9.5...
Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid 2.9.5 through 3.0.b3 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) auth.php and (2) auth_phpbb when the phpBB portal is enabled, and via a URL in the smf_root_path parameter in (3) auth.php and (4) auth_SMF when the SMF portal is enabled.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2283
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/433252/100/0/threaded
- http://www.vupen.com/english/advisories/2006/1726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26346
- http://www.securityfocus.com/archive/1/433253/100/0/threaded
- http://www.osvdb.org/25358
- http://www.securityfocus.com/bid/17875
- http://secunia.com/advisories/20027
- http://securityreason.com/securityalert/865
More from spiffyjr
View All →Affected Vendor
spiffyjr
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.