Multiple PHP Remote File Inclusion Vulnerabilities in Content*Builder by ContentBuilder
CVE-2006-3173
Currently unrated
What is CVE-2006-3173?
Content*Builder version 0.7.5 is susceptible to multiple PHP remote file inclusion vulnerabilities. These vulnerabilities allow remote attackers to exploit the system and execute arbitrary PHP code by manipulating specific parameters in the URL. The affected parameters include the path[cb] parameter in libraries/comment/postComment.php and modules/poll/poll.php, the rel parameter in modules/archive/overview.inc.php, and the actualModuleDir parameter in modules/forum/showThread.inc.php. Successful exploitation of these vulnerabilities can lead to unauthorized access and control of the affected server.
