Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
📦
pnphpbb
Vendor: postnuke_software_foundation
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
0
Remote Access
Total CVEs
4
Total Indexed
Avg. EPSS
4.62%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
6.8
CVSS
CVE-2007-6624
Exploit Found
Severity: MEDIUM
7.5
CVSS
CVE-2007-3052
Exploit Found
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.
Severity: HIGH
7.5
CVSS
CVE-2006-4968
Exploit Found
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Severity: HIGH