Detailed Description
Input passed to the "ModName" parameter in "modules/PNphpBB2/admin/admin_words.php", "modules/PNphpBB2/admin/admin_groups_reapir.php", "modules/PNphpBB2/admin/admin_smilies.php", "modules/PNphpBB2/admin/admin_ranks.php", "modules/PNphpBB2/admin/admin_styles.php", and "modules/PNphpBB2/admin/admin_users.php" is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal attacks and URL-encoded NULL bytes.
These vulnerabilities are confirmed in version 1.2i. Other versions may also be affected.