Vulnonym.com

CVE-2006-5281 - Spathic Destruction

Description

PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a URL in the skin parameter.

Reference

http://secunia.com/advisories/22250 http://securitydot.net/txt/id/1645/type/xpl/ http://www.osvdb.org/29692 http://www.securityfocus.com/bid/20462 http://www.vupen.com/english/advisories/2006/4013 https://exchange.xforce.ibmcloud.com/vulnerabilities/29431 https://www.exploit-db.com/exploits/2514