Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vegas78

#36563of 53,635
7.5Total CVSS
Vulnerabilities · 1
PT-2006-6153
7.5
2006-10-20
P News · P-News · CVE-2006-5434
**Name of the Vulnerable Software and Affected Versions** P-News versions 1.16 through 1.17 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `pn lang` parameter. This can be achieved by manipulating the API endpoint, although the specific endpoint is not mentioned. The estimated number of potentially affected devices and details about real-world incidents are not provided. **Recommendations** For P-News versions 1.16 through 1.17, consider restricting access to the `pn lang` parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.