CVE-2006-4631

SoftBB 0.1 - Code Injection

Title source: llm

Description

Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.

Exploits (2)

exploitdb WORKING POC VERIFIED
by DarkFig · perlwebappsphp
https://www.exploit-db.com/exploits/2300
exploitdb WORKING POC VERIFIED
by Kacper · phpwebappsphp
https://www.exploit-db.com/exploits/28488

Scores

EPSS 0.1328
EPSS Percentile 94.0%

Classification

Status draft

Affected Products (1)

softbb/softbb < 0.1

Timeline

Published Sep 08, 2006
Tracked Since Feb 18, 2026