CVE-2006-5094
phpBB XS 2 - Remote File Inclusion via phpbb_root_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5094. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpBB XS <= 0.58 by manipulating the `phpbb_root_path` parameter to include arbitrary remote scripts. The vulnerability arises from insecure handling of user-supplied input in the `include()` function.
Description
PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpBB XS <= 0.58 by manipulating the `phpbb_root_path` parameter to include arbitrary remote scripts. The vulnerability arises from insecure handling of user-supplied input in the `include()` function.