CVE-2006-5610

PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
References
Link Resource
http://secunia.com/advisories/22499 Vendor Advisory
http://secunia.com/advisories/22499 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:fully_modded_phpbb:fully_modded_phpbb:2021.4.40:*:*:*:*:*:*:*

History

03 Apr 2025, 16:15

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : unknown
v2 : 7.5
v3 : 9.8
CWE CWE-94

21 Nov 2024, 00:19

Type Values Removed Values Added
References () http://secunia.com/advisories/22499 - Vendor Advisory () http://secunia.com/advisories/22499 - Vendor Advisory

Information

Published : 2006-10-31 00:07

Updated : 2025-04-09 00:30


NVD link : CVE-2006-5610

Mitre link : CVE-2006-5610

CVE.ORG link : CVE-2006-5610


JSON object : View

Products Affected

fully_modded_phpbb

  • fully_modded_phpbb
CWE
NVD-CWE-Other CWE-94

Improper Control of Generation of Code ('Code Injection')