Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2481

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-2481
Last Modified 07 Mar 2011 10:09:15
Published 28 May 2008 11:32:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-2481

Summary

PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.

Vulnerable Systems

Application

  • Phpraider 1.0.7

  • Phpraider 1.0.7a


References

XF - phpraider-phpbb3functions-file-include(42622)

VUPEN - ADV-2008-1646

BID - 29356

MILW0RM - 5671

SECUNIA - 30375

CONFIRM - http://forums.phpraider.com/showthread.php?t=1087#v1_0_7b_-_May_29__2008


Last Updated: 27 May 2016 10:47:52