Intrusion Prevention

PAFileDB.Constants.PHP.Remote.File.Inclusion

Description

It indicates a possible exploit of a remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration that may allow remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

Affected Products

PHP Arena paFileDB 2.0.1
PHP Arena paFileDB 1.1.3
mxBB mxBB Portal 2.8
mxBB mxBB Portal 2.7

Impact

System compromise.

Recommended Actions

Refer to the vendor's web site for suggested workaround.
http://www.phparena.net/pafiledb/

CVE References

CVE-2006-2361