CVE-2006-2739

Epicdesigns tinyBB < 0.3 - Remote File Inclusion via tinybb_footers Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2739.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in tinyBB <= 0.3, including remote file inclusion (RFI) via the 'tinybb_footers' parameter, local file inclusion (LFI) via null byte injection, and SQL injection via the 'username' parameter in login.php. The RFI and LFI allow arbitrary file inclusion, while the SQL injection can bypass authentication.

Description

PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/1839

The exploit demonstrates multiple vulnerabilities in tinyBB <= 0.3, including remote file inclusion (RFI) via the 'tinybb_footers' parameter, local file inclusion (LFI) via null byte injection, and SQL injection via the 'username' parameter in login.php. The RFI and LFI allow arbitrary file inclusion, while the SQL injection can bypass authentication.

Classification
Working Poc 90%
Attack Type
Rce | Sqli | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: tinyBB <= 0.3
No auth needed
Prerequisites: Network access to the target application · PHP remote file inclusion enabled on the server
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20356
Exploit, Vendor Advisory x_refsource_misc
http://www.nukedx.com/?viewdoc=33
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016172
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18147
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26824
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/487311/100/200/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435281/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2035
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1011
Exploit, Vendor Advisory x_refsource_misc
http://www.nukedx.com/?getxpl=33

Scores

EPSS 0.0864
EPSS Percentile 94.4%

Details

Status published
Products (1)
epic_designs/tinybb < 0.3
Published Jun 01, 2006
Tracked Since Feb 18, 2026