PHPBB2 Install.PHP Remote File...

- AV AC AU C I A
发布: 2002-06-17
修订: 2025-04-13

A problem has been discovered in phpBB2 which may enable an attacker to include an arbitrary attacker-supplied file which is located on a remote host. An attacker may exploit this issue by supplying the location of a remote file as the value for the 'phpbb_root_path' URL parameter. In the case that the remote file is a PHP script, this may allow commands to be executed remotely with the privileges of the webserver. This is especially a concern for hosts running Microsoft Windows operating systems, as webservers are generally run with SYSTEM privileges on these platforms.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息