CVE-2006-4968
PNphpBB 1.2g - Remote File Inclusion via phpbb_root_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4968. PoCs published by AzzCoder.
AI-analyzed exploit summary This exploit leverages an uninitialized variable in PNphpBB2's functions_admin.php to include a remote shell via the phpbb_root_path parameter. The vulnerability allows arbitrary file inclusion leading to remote code execution.
Description
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Exploits (1)
This exploit leverages an uninitialized variable in PNphpBB2's functions_admin.php to include a remote shell via the phpbb_root_path parameter. The vulnerability allows arbitrary file inclusion leading to remote code execution.