HTTP: PHPBook Mail Field PHP Code Injection

This signature detects attempts to exploit a known vulnerability against PHPBook. A successful attack can lead to arbitrary code execution.

Extended Description

phpBook is prone to a vulnerability that may let remote attackers inject arbitrary PHP code into the application. This code may then be executed by visiting pages that include the injected code.

Affected Products

Phpbook phpbook

References

BugTraq: 16106

CVE: CVE-2006-0075

Short Name
HTTP:PHP:PHPBOOK-CODE-INJECTION
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2006-0075 Code Field Injection Mail PHP PHPBook bid:16106
Release Date
04/29/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Phpbook

CVSS Score

7.5

Found a potential security threat?