phorum-dbfile-file-include(30741)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/30741 CVE-2006-6550
Phorum 3.2.11 - 'common.php' Remote File Inclusion
Record summary
CVE-2006-6550 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPhorum 3.2.11 - 'common.php' Remote File InclusionExploitDB exploitby Mr-m07Not analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6550 2894exploit
https://www.exploit-db.com/exploits/2894