CVE-2006-5077
Minerva Build 238 and earlier - Remote File Inclusion via phpbb_root_path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5077. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in Minerva <= v238 due to improper input validation in the 'phpbb_root_path' parameter. An attacker can include arbitrary remote files by manipulating the URL, leading to potential remote code execution.
Description
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in Minerva <= v238 due to improper input validation in the 'phpbb_root_path' parameter. An attacker can include arbitrary remote files by manipulating the URL, leading to potential remote code execution.