Threat Encyclopedia
Nivisec.PHP.Root.Path.Remote.File.Inclusion
Description
It indicates a possible exploit of a remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module for phpBB, that may allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Affected Products
Nivisec User Viewed Posts Tracker 1.0
Impact
Compromise of affected system.
Recommended Actions
Currently we are not aware of any vendor-supplied patches for this issue.