Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-0859

Опубликовано: 02 мая 2005
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:czaries_network:czarnews:1.13b:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.17156
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

EPSS

Процентиль: 95%
0.17156
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other